Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 154216
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
99_loader_overflows.patch 99_loader_overflows.patch for imlib2-1.2.1 from Ubuntu patch Andreas Niederl 2006-11-06 05:32 0000 9.18 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 154216 depends on: Show dependency tree
Bug 154216 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-11-06 01:31 0000
Hello vapier, maybe some stuff for you when an update is avaible.



http://secunia.com/product/3880/

DESCRIPTION:
Some vulnerabilities have been reported in imlib2, which can be
exploited by malicious people to cause a DoS (Denial of Service) or
potentially compromise an application using the library.

The vulnerabilities are caused due to unspecified errors within the
processing of JPG, ARGB, PNG, LBM, PNM, TIFF, and TGA images. This
may be exploited to execute arbitrary code by e.g. tricking a user
into opening a specially crafted image file with an application using
imlib2.

SOLUTION:
Do not open untrusted images with an application using the library.

PROVIDED AND/OR DISCOVERED BY:
Ubuntu credits M. Joonas Pihlaja

ORIGINAL ADVISORY:
http://www.ubuntu.com/usn/usn-376-1

------- Comment #1 From Andreas Niederl 2006-11-06 05:30:42 0000 -------
Ubuntu seems to have a patch for this.
The new packages are linked on http://www.securityfocus.com/archive/1/450551
and when applying the Ubuntu-specific package patch to the original source tree
there appears a file debian/patches/99_loader_overflows.patch which supposedly
fixes this vulnerability.

------- Comment #2 From Andreas Niederl 2006-11-06 05:32:28 0000 -------
Created an attachment (id=101331) [details]
99_loader_overflows.patch for imlib2-1.2.1 from Ubuntu

------- Comment #3 From SpanKY 2006-11-06 07:12:03 0000 -------
ive used the actual fix committed upstream and added 1.3.0 with it

------- Comment #4 From Matthias Geerdsen 2006-12-13 04:12:09 0000 -------
looks like a forgotten bug here

1.3.0 has been marked stable on all arches

CVEs talk about <1.2.1 being affected, can someone confirm that <1.3.0 has been
affected as well?

looks like this will need a GLSA then

------- Comment #5 From Raphael Marichez 2006-12-15 07:55:33 0000 -------
(In reply to comment #4)

> CVEs talk about <1.2.1 being affected, can someone confirm that <1.3.0 has been
> affected as well?

that's a good question


> 
> looks like this will need a GLSA then
> 


i agree

------- Comment #6 From Sune Kloppenborg Jeppesen 2006-12-15 08:10:45 0000 -------
Yeah I think we need a GLSA for this one.

------- Comment #7 From Wolf Giesen (RETIRED) 2006-12-15 10:24:20 0000 -------
Seems to by my affirmative day today. "Yes".

------- Comment #8 From Raphael Marichez 2006-12-19 08:31:33 0000 -------
Hu, what are exactly the vulnerable and the fixed versions??

------- Comment #9 From Raphael Marichez 2006-12-21 05:47:09 0000 -------
GLSA 200612-20 , thanks everybody!

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug