CVE-2014-1958
published 2020-02-06CVE-2014-1958: Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.54%
88.0th percentile
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.7.7.10+dfsg-1 (bookworm) | imagemagick 8:6.7.7.10+dfsg-1 (bookworm) |
| imagemagick | imagemagick | < 6.8.8-5 | 6.8.8-5 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2014-03-06·CVSS 6.5
CVE-2012-0260 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs if it opened a specially
crafted image file.
Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that
ImageMagick incorrectly handled certain restart markers in JPEG images. If
a user or automated system using ImageMagick were tricked into opening a
specially crafted JPEG image, an attacker could exploit this to cause
memory consumption, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-0260)
It was discovered that ImageMagick incorrectly handled decoding certain PSD
images. If a user or automated system using ImageMagick were tricked into
opening a specially crafted PSD image, an attacker could exploit this to
cause a denial of service or
Debian
CVE-2014-1958: imagemagick - Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick b...
vendor_debian·2014·CVSS 8.8
CVE-2014-1958 [HIGH] CVE-2014-1958: imagemagick - Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick b...
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
Scope: local
bookworm: resolved (fixed in 8:6.7.7.10+dfsg-1)
bullseye: resolved (fixed in 8:6.7.7.10+dfsg-1)
forky: resolved (fixed in 8:6.7.7.10+dfsg-1)
sid: resolved (fixed in 8:6.7.7.10+dfsg-1)
trixie: resolved (fixed in 8:6.7.7.10+dfsg-1)
Red Hat
ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
vendor_redhat·2013-11-14·CVSS 8.8
CVE-2014-1958 [HIGH] ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6.
Package: ImageMagick (OpenShift Enterprise 1) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Not affected
GHSA
GHSA-6f4f-vqcj-cwvr: Buffer overflow in the DecodePSDPixels function in coders/psd
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2014-1958 [HIGH] GHSA-6f4f-vqcj-cwvr: Buffer overflow in the DecodePSDPixels function in coders/psd
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
OSV
CVE-2014-1958: Buffer overflow in the DecodePSDPixels function in coders/psd
osv·2020-02-06·CVSS 8.8
CVE-2014-1958 [HIGH] CVE-2014-1958: Buffer overflow in the DecodePSDPixels function in coders/psd
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding [fedora-all]
bugzilla·2014-02-20·CVSS 8.8
CVE-2014-1958 [HIGH] CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding [fedora-all]
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
bugzilla·2014-02-20·CVSS 8.8
CVE-2014-1958 [HIGH] CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding
A buffer overflow flaw was found in the way ImageMagick handled PSD images that use RLE encoding. An attacker could create a malicious PSD image file that, when opened in ImageMagick, would cause ImageMagick to crash or, potentially, execute arbitrary code with the privileges of the user running ImageMagick.
Upstream fix: http://trac.imagemagick.org/changeset/14801
References:
http://secunia.com/advisories/56844/
https://bugzilla.redhat.com/show_bug.cgi?id=1064098#c4
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1067277]
---
Reported upstream: http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=25128
---
(In reply to Pavel Alexeev (ak
Bugzilla
CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
bugzilla·2014-02-12·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
A buffer overflow flaw affecting ImageMagick versions prior to 6.8.8-5 when handling PSD images was reported:
http://secunia.com/advisories/56844/
Diffing ImageMagick-6.8.7/coders/psd.c and ImageMagick-6.8.8/coders/psd.c, it looks like the flaw may be FormatLocaleString() writing the amount of 6 long integers (approximately 48 bytes) into a buffer (layer_name) that is only 4 bytes:
""
@@ -1224,7 +1224,7 @@
Allocate layered image.
*/
layer_info[i].image=CloneImage(image,layer_info[i].page.width,
- layer_info[i].page.height == ~0U ? 1 : layer_info[i].page.height,
+ layer_info[i].page.height == ~0UL ? 1 : layer_info[i].page.height,
MagickFalse,&image->exception);
if (layer_info[i].image == (Image *) NULL)
{
@@ -2
http://lists.opensuse.org/opensuse-updates/2014-03/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00039.htmlhttp://trac.imagemagick.org/changeset/14801http://ubuntu.com/usn/usn-2132-1http://www.openwall.com/lists/oss-security/2014/02/13/2http://www.openwall.com/lists/oss-security/2014/02/13/5https://www.openwall.com/lists/oss-security/2014/02/19/13http://lists.opensuse.org/opensuse-updates/2014-03/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00039.htmlhttp://trac.imagemagick.org/changeset/14801http://ubuntu.com/usn/usn-2132-1http://www.openwall.com/lists/oss-security/2014/02/13/2http://www.openwall.com/lists/oss-security/2014/02/13/5https://www.openwall.com/lists/oss-security/2014/02/19/13
2020-02-06
Published