Bug 983750 (CVE-2014-9804) - VUL-0: CVE-2014-9804: ImageMagick.GraphicsMagick: Avoid a DOS in vision.c due to an infinite loop.
Summary: VUL-0: CVE-2014-9804: ImageMagick.GraphicsMagick: Avoid a DOS in vision.c due...
Status: RESOLVED INVALID
Alias: CVE-2014-9804
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Petr Gajdos
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-06-08 13:07 UTC by Marcus Meissner
Modified: 2016-06-09 11:09 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-06-08 13:07:35 UTC
* Avoid a DOS in vision.c due to an infinite loop.

seems to be:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=c504b8e1a1ca6f158f2d08bd33c62ce4865497ee


I am not seeing magick/vision.c in neither sle11 or sle12 IM or GM.

opensuse might be affected.
Comment 1 Swamp Workflow Management 2016-06-08 22:02:49 UTC
bugbot adjusting priority
Comment 2 Petr Gajdos 2016-06-09 11:09:29 UTC
Neither I am seeing vision.c or ConnectedComponentsImage(), even in 13.2 no.