| Name | CVE-2014-8355 |
| Description | PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read). |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-242-1, DLA-960-1 |
| Debian Bugs | 767240, 778238 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| graphicsmagick (PTS) | bookworm, bookworm (security) | 1.4+really1.3.40-4+deb12u1 | fixed |
| trixie | 1.4+really1.3.45+hg17696-1 | fixed |
| forky, sid | 1.4+really1.3.48-1 | fixed |
| imagemagick (PTS) | bookworm | 8:6.9.11.60+dfsg-1.6+deb12u11 | fixed |
| bookworm (security) | 8:6.9.11.60+dfsg-1.6+deb12u13 | fixed |
| trixie | 8:7.1.1.43+dfsg1-1+deb13u12 | fixed |
| trixie (security) | 8:7.1.1.43+dfsg1-1+deb13u11 | fixed |
| forky, sid | 8:7.1.2.31+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[squeeze] - imagemagick <no-dsa> (Minor issue)
https://int21.de/cve/CVE-2014-8355-pcx-oob-heap-overflow.html
[wheezy] - graphicsmagick <no-dsa> (Minor issue)
[squeeze] - graphicsmagick <no-dsa> (Minor issue)
http://sourceforge.net/p/graphicsmagick/code/ci/4426024497f9ed26cbadc5af5a5de55ac84796ff/ (graphicsmagick)