Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 176226 - media-gfx/gimp buffer overflow in sunras plugin (CVE-2007-2356)
Summary: media-gfx/gimp buffer overflow in sunras plugin (CVE-2007-2356)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/25012/
Whiteboard: A2 [glsa] p-y
Keywords:
Depends on: 168131
Blocks:
  Show dependency tree
 
Reported: 2007-04-27 11:29 UTC by Pierre-Yves Rofes (RETIRED)
Modified: 2007-05-11 02:04 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-04-27 11:29:38 UTC
Marsu has discovered a vulnerability in Gimp, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an error within the "set_color_table()" function in plug-ins/common/sunras.c. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted .RAS file.

Successful exploitation may allow the execution of arbitrary code.

The vulnerability is confirmed in version 2.2.14. Other versions may also be affected.

Solution:
Do not open untrusted .RAS files.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-04-27 11:31:11 UTC
setting status and cc'ing maintainer.
Comment 2 Hanno Böck gentoo-dev 2007-04-27 16:04:13 UTC
No patch, no upstream information...

I'll try to get some statement from upstream asap.
Comment 3 Hanno Böck gentoo-dev 2007-04-28 07:35:13 UTC
Bumped with patch from upstream svn. Fixed in 2.2.14 and 2.3.16.

Archs please go on with stablemarking 2.2.14.
Comment 4 Raúl Porcel (RETIRED) gentoo-dev 2007-04-28 16:03:05 UTC
ia64 + x86 stable
Comment 5 Hanno Böck gentoo-dev 2007-04-28 17:43:05 UTC
mips, fyi, I've removed the ~mips-keyword from 2.3.16, if you wanna have gimp 2.4 look that you get your dependencies ready.
Comment 6 Gustavo Zacarias (RETIRED) gentoo-dev 2007-04-30 17:42:58 UTC
sparc stable.
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2007-05-01 12:50:39 UTC
ppc64 stable
Comment 8 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-05-02 09:34:45 UTC
alpha stable.
Comment 9 Daniel Gryniewicz (RETIRED) gentoo-dev 2007-05-02 18:53:23 UTC
amd64 done.
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2007-05-03 18:42:30 UTC
ppc stable
Comment 11 Jeffrey Gardner (RETIRED) gentoo-dev 2007-05-04 16:22:27 UTC
gimp--2.2.14 fails with collision-detect on

* checking 1768 files for package collisions
existing file /usr/lib64/gimp/2.0/python/gimpenums.pyc is not owned by this package
existing file /usr/lib64/gimp/2.0/python/gimpfu.pyc is not owned by this package
1000 files checked ...
Comment 12 Hanno Böck gentoo-dev 2007-05-04 17:32:20 UTC
Jeffrey, collision with what? I can't think of another package owning these files, so I wonder why they are there on your system.
Comment 13 Jeroen Roovers (RETIRED) gentoo-dev 2007-05-05 12:06:13 UTC
hppa cannot currently test gimp, as we need glibc-2.5 stable before gimp will work (again). Right now, gimp does not even finish loading, and hangs before it could possibly do damage through this vulnerability. When hppa's glibc-2.5 ship comes in, I will be sure to revisit gimp, test it and mark it, but as for now, gimp cannot possibly pose a threat. Please move forward without us.
Comment 14 Hanno Böck gentoo-dev 2007-05-06 16:51:59 UTC
security: I think we're ready for GLSA.

collission-issues should be fixed now, but anyway, if they still occur, please open a new bug as they've nothing to do with this security-issue.
Comment 15 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-05-07 21:53:20 UTC
GLSA 200705-08 is out!
Comment 16 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-05-07 21:55:24 UTC
well hum, keeping opened in "enhancement" pending hppa/glibc resolution. Feel 
Comment 17 Hanno Böck gentoo-dev 2007-05-07 22:09:26 UTC
sorry for crashing the party, but I think the glsa is wrong.

It's not "fixed in >=2.2.14", but "fixed in (>=2.2.14 <2.2.999) and >=2.3.16.
It's important that ~-users update their gimp 2.3.x as well (and, of course, svn/9999-users shoudl re-merge).

Don't know if this is worth releasing an updated glsa, I leave this up to security.
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-08 05:49:07 UTC
2.3.x seems to be marked ~ so we don't consider that. However I do think that the GLSA lacks a warning for hppa users.
Comment 19 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-05-08 06:13:58 UTC
Hi jer or any member of HPPA team,

please could you fix the keywording stuff of gimp so that the hppa users don't remain with an apparently/possibly vulnerable version on their system:

- either mark stable 2.2.14,

- either dekeyword 2.2.*,

as you prefer, thanks
Comment 20 Jeroen Roovers (RETIRED) gentoo-dev 2007-05-08 14:27:09 UTC
(In reply to comment #19)
> Hi jer or any member of HPPA team,

Hi there!

> - either mark stable 2.2.14,

Done.
Comment 21 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-05-08 20:04:49 UTC
Thanks Jeroen
Comment 22 Joshua Kinard gentoo-dev 2007-05-11 02:04:26 UTC
mips done