Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 549344 - <media-gfx/ufraw-0.21-r1: input sanitization errors (CVE-2015-3885)
Summary: <media-gfx/ufraw-0.21-r1: input sanitization errors (CVE-2015-3885)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: 591210
Blocks:
  Show dependency tree
 
Reported: 2015-05-13 07:35 UTC by Agostino Sarubbo
Modified: 2017-02-22 10:38 UTC (History)
1 user (show)

See Also:
Package list:
=media-gfx/ufraw-0.22
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-05-13 07:35:34 UTC
From ${URL} :

#2015-006 dcraw input sanitization errors

Description:

The dcraw photo decoder is an open source project for raw image parsing.

The dcraw tool, as well as several other projects re-using its code, suffers
from an integer overflow condition which lead to a buffer overflow. The
vulnerability concerns the 'len' variable, parsed without validation from
opened images, used in the ljpeg_start() function.

A maliciously crafted raw image file can be used to trigger the vulnerability,
causing a Denial of Service condition.

Affected version:

   dcraw >= 7.00
   UFRaw >= 0.5
   LibRaw <= 0.16.0, 0.17-Alpha2
   RawTherapee >= 3.0
   CxImage >= 6.00
   Rawstudio >= 0.1
   Kodi >= 10.0
   ExactImage >= 0.1.0

Fixed version:

   dcraw, N/A
   UFRaw, N/A
   LibRaw >= 0.16.1, 0.17-Alpha3
   RawTherapee, N/A
   CxImage, N/A
   Rawstudio, N/A
   Kodi, N/A
   ExactImage, N/A

Credit: vulnerability report from Eduardo Castellanos <guayin [at] gmail [dot]
com>.

CVE: N/A

Timeline:

2015-04-24: vulnerability report received
2015-04-27: contacted dcraw maintainer
2015-04-30: patch provided by maintainer
2015-05-04: reporter confirms patch
2015-05-11: contacted additional affected vendors
2015-05-11: advisory release

References:
https://github.com/LibRaw/LibRaw/commit/4606c28f494a750892c5c1ac7903e62dd1c6fdb5
https://github.com/rawstudio/rawstudio/commit/983bda1f0fa5fa86884381208274198a620f006e

Permalink:
http://www.ocert.org/advisories/ocert-2015-006.html


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Markus Meier gentoo-dev 2015-05-22 21:30:43 UTC
Should be fixed in cvs, applied the patch from upstream bug / cvs-commit http://sourceforge.net/p/ufraw/bugs/396/

+*ufraw-0.21-r1 (22 May 2015)
+
+  22 May 2015; Markus Meier <maekke@gentoo.org> +ufraw-0.21-r1.ebuild,
+  +files/ufraw-0.21-CVE-2015-3885.patch:
+  bump for security bug #549344
+
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2017-02-01 01:42:39 UTC
No PoC for ACE/RCE.  Downgraded.  Please cleanup the vulnerable versions.

GLSA Vote: No
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2017-02-22 10:38:55 UTC
tree is clean