Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 137344 - media-libs/netpbm: <10.34 DoS
Summary: media-libs/netpbm: <10.34 DoS
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/20729/
Whiteboard: B3 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-20 01:56 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2019-12-25 20:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-20 01:56:52 UTC
Very very minor IMHO, because it only crashes the application, which is not a server... so the impact is... ~ null

Nonetheless, graphics team, can you bump out the 10.34 version ?



Software:	NetPBM 10.x

Description:
A vulnerability has been reported in NetPBM, which can be exploited by malicious people to cause a DoS (Denial of Service) .

The vulnerability is caused due to an off-by-one boundary error within "pamtofits". This can be exploited to cause a single byte buffer overflow when processing a specially crafted input file.

Successful exploitation crashes the application. Code execution has not been confirmed. However, this can't be ruled out completely.

The vulnerability has been reported in versions 10.30 through 10.33.

Solution:
Update to version 10.34.
http://sourceforge.net/project/showfiles.php?group_id=5128

Provided and/or discovered by:
Reported by vendor.

Original Advisory:
http://sourceforge.net/project/shownotes.php?release_id=425770
Comment 1 Wolf Giesen (RETIRED) gentoo-dev 2006-06-20 02:01:40 UTC
tinderbox says it's used by mail-mta/courier and hylafax, for example, which are server apps.
Comment 2 SpanKY gentoo-dev 2006-06-20 12:23:58 UTC
10.34 in portage
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-21 05:06:12 UTC
Thanks Vapier;

Hello arches, please mark stable -10.34
Comment 4 Gustavo Zacarias (RETIRED) gentoo-dev 2006-06-21 06:22:20 UTC
sparc stable.
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2006-06-21 13:49:45 UTC
ppc64 stable
Comment 6 Joshua Jackson (RETIRED) gentoo-dev 2006-06-21 22:59:16 UTC
x86 done
Comment 7 Thomas Cort (RETIRED) gentoo-dev 2006-06-22 21:01:55 UTC
stable on alpha and amd64.
Comment 8 René Nussbaumer (RETIRED) gentoo-dev 2006-06-24 11:09:47 UTC
stable on hppa
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-25 00:28:40 UTC
ppc stable
Comment 10 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-25 11:42:16 UTC
time to vote.

i would vote a half-no (half, because netpbm is used in other softwares)
Comment 11 Wolf Giesen (RETIRED) gentoo-dev 2006-06-25 11:56:39 UTC
Definite yes.
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2006-06-26 13:24:31 UTC
I vote no. Who/what server app would use *pamtofits* on untrusted input ?? It's not like if all NetPBM utilities were affected.
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-28 02:33:18 UTC
Voting NO and closing. Feel free to reopen if you disagree.
Comment 14 Ryan Grange 2006-07-01 10:38:50 UTC
Attempting to update to netpbm-10.34 fails because it is dependant on features not available until GCC-4 which has at this time only been marked stable for HPPA and PPC.