CVE-2014-1947: ImageMagick

High severity, CVSS 7.8. EPSS: 7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.

Affected products

  • ImageMagick ImageMagick: up to and including 6.5.4
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Software Development Kit: version 11 only

Published 2020-02-17. Last modified 2026-06-17.