CVE-2014-9826Imagemagick vulnerability

CWE-3887 documents7 sources
Severity
9.8CRITICALNVD
EPSS
3.4%
top 12.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMay 17

Description

ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

debiandebian/imagemagick< imagemagick 8:6.8.9.9-4 (bookworm)
Debianimagemagick/imagemagick< 8:6.8.9.9-4+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-64hf-cr4p-qj5v: ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files2022-05-17
OSV
CVE-2014-9826: ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files2017-03-30

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2016-11-21
Red Hat
ImageMagick: incorrect error handling in sun files2014-12-24
Debian
CVE-2014-9826: imagemagick - ImageMagick allows remote attackers to have unspecified impact via vectors relat...2014

💬Community

1
Bugzilla
CVE-2014-9826 ImageMagick: incorrect error handling in sun files2016-06-07