Bug 1083477 (CVE-2014-2030)

Summary: CVE-2014-2030 ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
Product: [Other] Security Response Reporter: Stefan Cornelius <scorneli>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bleanhar, btissoir, ccoleman, dmcphers, jdetiber, jialiu, jkurik, kseifried, lmeyer, nmurray, oregonhill, pahan, pfrields
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-04-04 13:47:38 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1067278, 1083080    
Bug Blocks: 1064101    

Description Stefan Cornelius 2014-04-02 10:25:13 UTC
A buffer overflow flaw affecting ImageMagick when creating PSD images was reported. The vulnerability is similar to CVE-2014-1947, except that CVE-2014-2030's format string is "L%06ld" instead of CVE-2014-1947's "L%02ld" due to commit r1448: http://trac.imagemagick.org/changeset/1448

Fixed by commit r13736: http://trac.imagemagick.org/changeset/13736

Comment 1 Tomas Hoger 2014-04-04 13:40:00 UTC
The related CVE-2014-1947 issue is tracked via bug 1064098.

Comment 2 Stefan Cornelius 2014-04-04 13:47:38 UTC
Statement:

Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6.

Comment 3 oregonhill 2024-02-22 05:32:50 UTC
PSD writing layer name buffer overflow vulnerability poses a significant risk to digital design projects. It can lead to data corruption or even system crashes if exploited. For students seeking reliable academic assistance, platforms like EduBirdie are invaluable. By reading reviews on platforms such as https://www.reviews.io/company-reviews/store/edubirdie.com, students can gain insights into the experiences of others and make informed decisions about the writers they choose to work with.