CVE-2014-9847

CWE-119Buffer Overflow8 documents8 sources
Severity
9.8CRITICAL
EPSS
5.8%
top 9.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 14

Description

The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages10 packages

Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 16.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pw5h-pj9g-x2j5: The jng decoder in ImageMagick 62022-05-14
CVEList
CVE-2014-9847: The jng decoder in ImageMagick 62017-03-20
OSV
CVE-2014-9847: The jng decoder in ImageMagick 62017-03-20

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2016-11-21
Red Hat
ImageMagick: incorrect handling of "previous" image in the JNG decoder2014-12-24
Debian
CVE-2014-9847: imagemagick - The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspec...2014

💬Community

1
Bugzilla
CVE-2014-9847 ImageMagick: incorrect handling of "previous" image in the JNG decoder2016-06-07