CVE-2014-1958Classic Buffer Overflow in Imagemagick

Severity
8.8HIGHNVD
EPSS
1.1%
top 21.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 17

Description

Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/imagemagick< imagemagick 8:6.7.7.10+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.7.7.10+dfsg-1+3
NVDopensuse/opensuse11.4, 12.3, 13.1+2

Also affects: Ubuntu Linux 12.04, 12.10, 13.10

🔴Vulnerability Details

2
GHSA
GHSA-6f4f-vqcj-cwvr: Buffer overflow in the DecodePSDPixels function in coders/psd2022-05-17
OSV
CVE-2014-1958: Buffer overflow in the DecodePSDPixels function in coders/psd2020-02-06

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2014-03-06
Debian
CVE-2014-1958: imagemagick - Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick b...2014
Red Hat
ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding2013-11-14

💬Community

3
Bugzilla
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding [fedora-all]2014-02-20
Bugzilla
CVE-2014-1958 ImageMagick: buffer overflow flaw when handling PSD images that use RLE encoding2014-02-20
Bugzilla
CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")2014-02-12
CVE-2014-1958 — Classic Buffer Overflow in Imagemagick | cvebase