Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 141577 - media-libs/gd DoS issue
Summary: media-libs/gd DoS issue
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2006-07-24 06:25 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2019-12-26 10:26 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
gd-patches.tar.bz2 (gd-patches.tar.bz2,26.91 KB, application/octet-stream)
2006-11-02 13:58 UTC, INODE64 Sistemas
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-24 06:25:16 UTC
See bug #135860 for further details.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-24 06:26:01 UTC
Mike please advise and patch as necessary.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2006-08-12 05:25:14 UTC
vapier, please advise/fix. kthanx
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-05 06:16:12 UTC
Vapier, any news on this one?
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-13 23:16:54 UTC
Vapier, any news on this one?
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-26 09:26:30 UTC
Vapier, any news on this one?
Comment 6 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-03 08:39:09 UTC
<@SpanKY> vorlon078: need to contact upstream as they havent done a release yet
Comment 7 INODE64 Sistemas 2006-11-02 13:58:29 UTC
Created attachment 101093 [details]
gd-patches.tar.bz2

update gd with debian patches:

1001_CAN-2004-0941.patch
1002_CVE-2006-2906.patch
1003_fix_aa_segfault.patch
1004_improve_aa_lines.patch
1005_graphviz_sanitize.patch
1006_western_european_fonts.patch
1007_minimize_linking_deps.patch
1008_segfault_invalid_gif.patch
Comment 8 Matthias Geerdsen (RETIRED) gentoo-dev 2006-11-06 04:07:35 UTC
vapier, could you check/apply the needed patch for this issue?
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-16 06:29:36 UTC
Vapier, any news on this one?
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-24 12:21:20 UTC
Vapier, any news on this one?
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-12-11 08:32:25 UTC
Vapier, any news on this one?
Comment 12 Jakub Moc (RETIRED) gentoo-dev 2007-01-17 13:42:32 UTC
Just an update here, thanks to koredn from #gentoo-php

This project has been moved and is being developed by Pierre Joye (a PHP dev).

<Pierre> kore_: it is already fixed, in gd cvs and php-src (in a cleaner way btw)" 
<kore_> Pierre, Is there already a ETA for a 2.0.34 release?                                                                
< koredn> <Pierre> kore_: RC should go out shortly (waiting some autoconf commit)

http://cvs.php.net/viewcvs.cgi/gd/libgd/

According to Pierre, Gentoo developers already know about this... :P Anyway, unless vapier feels like doing something here, I'll try to ask CHTEKK to take over this and stick the package under PHP herd.
Comment 13 SpanKY gentoo-dev 2007-01-17 16:48:07 UTC
yes, "Gentoo developers" already know this because i've been talking to Pierre on the GD development lists ... fancy that
Comment 14 Jakub Moc (RETIRED) gentoo-dev 2007-01-17 17:25:22 UTC
(In reply to comment #13)
> yes, "Gentoo developers" already know this because i've been talking to Pierre
> on the GD development lists ... fancy that

Wonderful, then maybe you could have responded to one of the 9 pings on this bug... I'm afraid security folks are missing paranormal skills :P
Comment 15 Nuno Lopes 2007-01-24 23:46:13 UTC
Pierre (the new gd maintainer) asked me to post the following comment:

For the record, I strongly recommend to do not apply all patches from debian but from the libgd CVS.

A couple of patches listed here should not be applied at all, no matter the distribution:
1006_western_european_fonts.patch
1004_improve_aa_lines.patch

1005_graphviz_sanitize.patch is unknown to me or maybe already committed as I applied almost all graphiz patches sent to T. Boutell (will download it and compare later this week).

As Vapier said earlier, he follows the list and can contact me for any further informations. I will be happy to help gentoo to bring some order in the patch mess.

Thanks for your work and heads up :)
Comment 16 SpanKY gentoo-dev 2007-02-07 04:26:55 UTC
sure, i should have kept security devs informed ... but that doesnt mean i need some lackey who thinks he knows how to help

gd-2.0.34 in portage
Comment 17 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-10 19:29:13 UTC
Thanks vapier, arches please test gd-2.0.34 and mark stable if appropriate , thanks a lot
Comment 18 Christian Faulhammer (RETIRED) gentoo-dev 2007-02-11 09:55:08 UTC
x86 stable
Comment 19 Tobias Scherbaum (RETIRED) gentoo-dev 2007-02-11 11:17:37 UTC
ppc stable
Comment 20 René Nussbaumer (RETIRED) gentoo-dev 2007-02-11 21:47:36 UTC
Stable on hppa
Comment 21 Simon Stelling (RETIRED) gentoo-dev 2007-02-12 00:00:35 UTC
amd64 stable 
Comment 22 Bryan Østergaard (RETIRED) gentoo-dev 2007-02-12 00:03:03 UTC
Stable on IA64.
Comment 23 Gustavo Zacarias (RETIRED) gentoo-dev 2007-02-12 13:00:47 UTC
sparc stable.
Comment 24 Bryan Østergaard (RETIRED) gentoo-dev 2007-02-12 20:29:28 UTC
Stable on Alpha.
Comment 25 Markus Rothe (RETIRED) gentoo-dev 2007-02-13 08:38:08 UTC
ppc64 stable
Comment 26 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-13 10:30:11 UTC
Thanks all, time to vote for a GLSA:

i vote yes because it's an infinite loop (cpu consumption) that could be triggered through a PHP script using gd, for example, or any other server-oriented application calling gd.
Comment 27 Tavis Ormandy (RETIRED) gentoo-dev 2007-02-13 11:12:33 UTC
I would vote NO, as the impact is fairly minor.
Comment 28 Matthias Geerdsen (RETIRED) gentoo-dev 2007-02-22 20:35:34 UTC
I agree with falco here

voting yes
Comment 29 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-03-03 17:32:08 UTC
back to [noglsa] after having talked with the discoverer who says that it doesn't merit an update.
Although there is a possible incrementation of the pointer on the NULL char, it seems very very hard to obtain.
Feel free to reopen if you disagree.