Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 217047 (CVE-2008-1382) - media-libs/libpng <1.2.26-r1 zero-length unknown chunks memory overwrite (CVE-2008-1382)
Summary: media-libs/libpng <1.2.26-r1 zero-length unknown chunks memory overwrite (CVE...
Status: RESOLVED FIXED
Alias: CVE-2008-1382
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2/B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-09 19:20 UTC by Robert Buchholz (RETIRED)
Modified: 2020-04-08 21:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
libpng-CVE-2007-6070.patch (libpng-CVE-2007-6070.patch,7.63 KB, patch)
2008-04-09 19:22 UTC, Robert Buchholz (RETIRED)
no flags Details | Diff
libpng-1.2.26-r1-CVE-2007-6070.tar.lzma (libpng-1.2.26-r1-CVE-2007-6070.tar.lzma,2.48 KB, application/octet-stream)
2008-04-10 05:01 UTC, SpanKY
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-09 19:20:56 UTC
libpng does not correctly handle unknown zero-length chunks, which could
result in writing to attacker controlled addresses, depending on how the
libpng api is used.

Vapier, this issue is under embargo until 2008-04-12. Do not commit anything to
CVS until this date. Please prepare an updated ebuild and attach it to this
bug, we will do prestable testing here. Thanks.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-04-09 19:22:08 UTC
Created attachment 149228 [details, diff]
libpng-CVE-2007-6070.patch

Upstream patch.
Comment 2 SpanKY gentoo-dev 2008-04-10 05:01:47 UTC
Created attachment 149262 [details]
libpng-1.2.26-r1-CVE-2007-6070.tar.lzma

pretty straightforward ...
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-04-10 09:09:27 UTC
Arch Security Liaisons, please test the attached ebuild and report it stable on this bug.
Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 release s390 sh sparc x86"

CC'ing current Liaisons:
   alpha : ferdy
   amd64 : welp
    hppa : jer
     ppc : dertobi123
   ppc64 : corsair
 release : pva
   sparc : fmccor
     x86 : opfer

vapier, please note that CVE-2007-6070 has been dropped in favour of CVE-2008-1382 for this issue.
Comment 4 Ferris McCormick (RETIRED) gentoo-dev 2008-04-10 13:46:32 UTC
sparc looks good (patch installs, -r1 builds and passes its tests).
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2008-04-10 16:43:59 UTC
Works for HPPA.
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2008-04-10 18:05:16 UTC
Looks okay on alpha/ia64/x86
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2008-04-10 18:15:16 UTC
looks good on ppc64
Comment 8 Tobias Scherbaum (RETIRED) gentoo-dev 2008-04-10 18:53:42 UTC
looks good on ppc
Comment 9 Markus Meier gentoo-dev 2008-04-11 20:33:53 UTC
Looks good on amd64/x86
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2008-04-14 01:36:03 UTC
vapier, can you please commit the ebuild to CVS with the keywords gathered in this bug. Please rename the patch to reflect that CVE-2008-1382 should be used for the issue.
Comment 11 SpanKY gentoo-dev 2008-04-14 03:04:18 UTC
added to the tree
Comment 12 Matthias Geerdsen (RETIRED) gentoo-dev 2008-04-14 08:10:32 UTC
vapier, could you set the keywords as approved by arch liaisons in here, so that the GLSA can go out as soon as it is approved

up to now the following arches gave their "looks good":
alpha amd64 hppa ia64 ppc ppc64 sparc x86

final target is:
KEYWORDS="alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 s390 sh sparc ~sparc-fbsd x86 ~x86-fbsd"

so cc'ing remaining arches as well as release since there was no comment from them yet
Comment 13 Robert Buchholz (RETIRED) gentoo-dev 2008-04-15 01:19:46 UTC
(In reply to comment #12)
> vapier, could you set the keywords as approved by arch liaisons in here, so
> that the GLSA can go out as soon as it is approved

I marked stable for the keywords. base-system was not in CC on the bug anymore.
Comment 14 Robert Buchholz (RETIRED) gentoo-dev 2008-04-15 03:01:52 UTC
GLSA 200804-15
Comment 15 Peter Volkov (RETIRED) gentoo-dev 2008-04-21 07:57:08 UTC
Fixed in release snapshot.