Vulnerabilities > CVE-2014-1947 - Out-of-bounds Write vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
description | ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH). CVE-2014-1947,CVE-2014-2030. Local exploit for windows platform |
id | EDB-ID:31688 |
last seen | 2016-02-03 |
modified | 2014-02-16 |
published | 2014-02-16 |
reporter | Mike Czumak |
source | |
title | ImageMagick 6.8.8-4 - Local Buffer Overflow SEH |
NASL family Amazon Linux Local Security Checks
NASL id ALA_ALAS-2014-420.NASL
description A buffer overflow flaw affecting ImageMagick and GraphicsMagic when handling PSD images was reported.
last seen 2020-03-17
modified 2014-10-12
plugin id 78363
published 2014-10-12
reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
source
title Amazon Linux AMI : GraphicsMagick (ALAS-2014-420)
NASL family Fedora Local Security Checks
NASL id FEDORA_2014-14617.NASL
description Fix for psd security issue, and upgrade path to f21.
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
last seen 2020-03-17
modified 2014-11-17
plugin id 79260
published 2014-11-17
reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
source
title Fedora 21 : GraphicsMagick-1.3.20-3.fc21 (2014-14617)
NASL family SuSE Local Security Checks
NASL id SUSE_11_IMAGEMAGICK-140307.NASL
description The image converter program and library set of ImageMagick received an update that fixes a buffer overflow when handling PSD images.
last seen 2020-06-05
modified 2014-03-13
plugin id 72977
published 2014-03-13
reporter This script is Copyright (C) 2014-2020 Tenable Network Security, Inc.
source
title SuSE 11.3 Security Update : ImageMagick (SAT Patch Number 8978)
NASL family Solaris Local Security Checks
NASL id SOLARIS11_IMAGEMAGICK_20140731.NASL
description The remote Solaris system is missing necessary patches to address security updates.
last seen 2020-06-01
modified 2020-06-02
plugin id 80644
published 2015-01-19
reporter This script is Copyright (C) 2015-2018 Tenable Network Security, Inc.
source
title Oracle Solaris Third-Party Patch Update : imagemagick (multiple_buffer_errors_vulnerabilities_in2)
NASL family Gentoo Local Security Checks
NASL id GENTOO_GLSA-201405-09.NASL
description The remote host is affected by the vulnerability described in GLSA-201405-09 (ImageMagick: Multiple vulnerabilities)
Multiple vulnerabilities have been discovered in ImageMagick. Please review the CVE identifiers referenced below for details. Note that CVE-2012-1185 and CVE-2012-1186 were issued due to incomplete fixes for CVE-2012-0247 and CVE-2012-0248, respectively. The earlier CVEs were addressed in GLSA 201203-09.
Impact : A remote attacker can utilize multiple vectors to execute arbitrary code or cause a Denial of Service condition.
Workaround : There is no known workaround at this time.
last seen 2020-06-01
modified 2020-06-02
plugin id 74052
published 2014-05-19
reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
source
title GLSA-201405-09 : ImageMagick: Multiple vulnerabilities
NASL family Fedora Local Security Checks
NASL id FEDORA_2014-9624.NASL
description New stable upstream release, patched for CVE-2014-1947. See also:
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
last seen 2020-03-17
modified 2014-09-15
plugin id 77678
published 2014-09-15
reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
source
title Fedora 19 : GraphicsMagick-1.3.20-3.fc19 (2014-9624)
