Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 611356 (CVE-2017-6335)

Summary: [TRACKER] Heap out-of-bounds read in tiff.c
Product: Gentoo Security Reporter: Thomas Deutschmann (RETIRED) <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal Keywords: Tracker
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://seclists.org/oss-sec/2017/q1/494
Whiteboard:
Package list:
Runtime testing required: ---
Bug Depends on: 611358, 611360    
Bug Blocks:    

Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-02 00:18:50 UTC
ImageMagick and GraphicsMagick encounter a read beyond an allocated heap buffer when reading CMYKA TIFF files which claim to offer fewer samples per pixel than required. A maliciously crafted file could cause the application to crash.

References:

http://seclists.org/oss-sec/2017/q1/494

Upstream patch:

https://sourceforge.net/p/graphicsmagick/code/ci/6156b4c2992d855ece6079653b3b93c3229fc4b8/
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-03-27 02:23:13 UTC
All dependent bugs fixed.