Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 611358

Summary: <media-gfx/graphicsmagick-1.3.26: Heap out-of-bounds read in tiff.c
Product: Gentoo Security Reporter: Thomas Deutschmann (RETIRED) <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa cve]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 611356    

Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-02 00:22:07 UTC
GraphicsMagick encounter a read beyond an allocated heap buffer when reading CMYKA TIFF files which claim to offer fewer samples per pixel than required. A maliciously crafted file could cause the application to crash. Please see bug 611356 for details.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-02 00:26:32 UTC
Probably only affected when "tiff" USE flag is set which isn't the default.

Upstream patch: https://sourceforge.net/p/graphicsmagick/code/ci/6156b4c2992d855ece6079653b3b93c3229fc4b8/
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2017-10-23 00:12:35 UTC
GLSA Vote: No

Cleanup tracked in bug #631562