CVE Vulnerabilities

CVE-2014-9807

Double Free

Published: Mar 30, 2017 | Modified: Oct 31, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 6.9.4-0 (excluding)
Imagemagick Ubuntu precise *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu upstream *

Potential Mitigations

References