Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 264604
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
lcms-CVE-2009-0793.patch lcms-CVE-2009-0793.patch patch Robert Buchholz 2009-04-02 10:55 0000 741 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 264604 depends on: Show dependency tree
Bug 264604 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-04-02 10:53 0000
** Please note that this issue is confidential and no information should be
disclosed until it is made public, see "Whiteboard" for a date **

On Monday 30 March 2009, Jan Lieskovsky wrote:
  A null pointer dereference flaw was found in the
LittleCMS color management system (lcms) in 
the way lcms performs transformation operations
when creating gray input matrix shaper. Processing
a malicious image file, with specially-crafted
ICC profile, could lead to denial of service.

CVE information: CVE-2009-0793 has been already assigned.

Proposed embargo date: 2009-04-02

------- Comment #1 From Robert Buchholz 2009-04-02 10:54:26 0000 -------
This is going public today. It would be preferable if we could bump to lcms
1.18 and apply the patch on top later when RedHat opens up the embargo.

------- Comment #2 From Robert Buchholz 2009-04-02 10:55:21 0000 -------
Created an attachment (id=187064) [details]
lcms-CVE-2009-0793.patch

------- Comment #3 From Robert Buchholz 2009-04-06 08:57:48 0000 -------
This is now public. Since the patch is pretty non-intrusive, it could be
applied easily. However, I contacted upstream concerning a new release
timeframe.

------- Comment #4 From Daniel Gryniewicz 2009-04-06 13:41:39 0000 -------
Added and bumped to 1.18-r1.  Sorry for the slow turnaround...

------- Comment #5 From Robert Buchholz 2009-04-12 15:32:16 0000 -------
upstream is currently conduction regression tests on the patch. I suggest we
wait until they have been completed. This bug should only allow for a DoS
anyway.

------- Comment #6 From Stefan Behte 2009-04-15 21:51:57 0000 -------
CVE-2009-0793 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0793):
  cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in
  OpenJDK and other products, allows remote attackers to cause a denial
  of service (NULL pointer dereference and application crash) via a
  crafted image that triggers execution of incorrect code for
  "transformations of monochrome profiles."

------- Comment #7 From Robert Buchholz 2009-04-18 11:15:31 0000 -------
Upstream has confirmed the patch and will release it as 1.18a later.

------- Comment #8 From Robert Buchholz 2009-04-18 11:15:59 0000 -------
Arches, please test and mark stable:
=media-libs/lcms-1.18-r1
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"

------- Comment #9 From Markus Meier 2009-04-18 12:37:20 0000 -------
amd64/x86 stable

------- Comment #10 From Brent Baude 2009-04-18 13:14:40 0000 -------
ppc64 done

------- Comment #11 From Brent Baude 2009-04-18 13:14:47 0000 -------
ppc done

------- Comment #12 From Jeroen Roovers 2009-04-18 16:36:33 0000 -------
Stable for HPPA.

------- Comment #13 From Tobias Klausmann 2009-04-18 16:44:57 0000 -------
Stable on alpha.

------- Comment #14 From Raúl Porcel 2009-04-18 17:08:23 0000 -------
arm/ia64/s390/sh/sparc stable

------- Comment #15 From Alex Legler 2009-04-18 21:13:12 0000 -------
GLSA together with bug 260269.

------- Comment #16 From Pierre-Yves Rofes 2009-04-19 15:45:32 0000 -------
GLSA 200904-19

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug