7.5
CVE-2014-9851
- EPSS 3.7%
- Veröffentlicht 20.03.2017 16:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse Project ≫ Leap Version 42.1
Opensuse Project ≫ Suse Linux Enterprise Debuginfo Version 11.0 Update sp4
Opensuse Project ≫ Suse Linux Enterprise Desktop Version 12.0 Update sp1
Opensuse Project ≫ Suse Linux Enterprise Server Version 11.0 Update sp4
Opensuse Project ≫ Suse Linux Enterprise Server Version 12.0 Update sp1
Opensuse Project ≫ Suse Linux Enterprise Software Development Kit Version 11.0 Update sp4
Opensuse Project ≫ Suse Linux Enterprise Software Development Kit Version 12.0 Update sp1
Opensuse Project ≫ Suse Linux Enterprise Workstation Extension Version 12.0 Update sp1
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.10
Imagemagick ≫ Imagemagick Version 6.8.8-9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.7% | 0.884 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.openwall.com/lists/oss-security/2016/06/02/13
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00009.html
http://www.ubuntu.com/usn/USN-3131-1
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=33b2d377b94eb738011bc7d5e90ca0a16ce4d471
https://bugzilla.redhat.com/show_bug.cgi?id=1343511