Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 611356 (CVE-2017-6335)

Summary: [TRACKER] Heap out-of-bounds read in tiff.c
Product: Gentoo Security Reporter: Thomas Deutschmann <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: normal Keywords: Tracker
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Package list:
Runtime testing required: ---
Bug Depends on: 611358, 611360    
Bug Blocks:    

Description Thomas Deutschmann gentoo-dev 2017-03-02 00:18:50 UTC
ImageMagick and GraphicsMagick encounter a read beyond an allocated heap buffer when reading CMYKA TIFF files which claim to offer fewer samples per pixel than required. A maliciously crafted file could cause the application to crash.


Upstream patch:
Comment 1 Aaron Bauman Gentoo Infrastructure gentoo-dev Security 2018-03-27 02:23:13 UTC
All dependent bugs fixed.