CVE-2014-9915
published 2017-03-23CVE-2014-9915: Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
PriorityP413medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.87%
55.2th percentile
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.8.9.9-1 (bookworm) | imagemagick 8:6.8.9.9-1 (bookworm) |
| imagemagick | imagemagick | <= 6.6.0-3 | — |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-1 | 8:6.8.9.9-1 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-1 | 8:6.8.9.9-1 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-1 | 8:6.8.9.9-1 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-1 | 8:6.8.9.9-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24m7-fg2x-3vfx: Off-by-one error in ImageMagick before 6
ghsa_unreviewed·2022-05-17
CVE-2014-9915 [MEDIUM] GHSA-24m7-fg2x-3vfx: Off-by-one error in ImageMagick before 6
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
OSV
CVE-2014-9915: Off-by-one error in ImageMagick before 6
osv·2017-03-23·CVSS 5.5
CVE-2014-9915 [MEDIUM] CVE-2014-9915: Off-by-one error in ImageMagick before 6
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
Red Hat
ImageMagick: Off-by-one count when parsing an 8BIM profile
vendor_redhat·2014-10-29·CVSS 5.5
CVE-2014-9915 [MEDIUM] CWE-193 ImageMagick: Off-by-one count when parsing an 8BIM profile
ImageMagick: Off-by-one count when parsing an 8BIM profile
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 7) - Will not fix
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2014-9915: imagemagick - Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause ...
vendor_debian·2014·CVSS 5.5
CVE-2014-9915 [MEDIUM] CVE-2014-9915: imagemagick - Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause ...
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-1)
bullseye: resolved (fixed in 8:6.8.9.9-1)
forky: resolved (fixed in 8:6.8.9.9-1)
sid: resolved (fixed in 8:6.8.9.9-1)
trixie: resolved (fixed in 8:6.8.9.9-1)
No detection rules found.
No public exploits indexed.
2017-03-23
Published