Summary: | <media-gfx/imagemagick-{6.9.11.1,7.0.10.1}: Possible buffer overflow in ComplexImages() | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | graphics+disabled, slyfox |
Priority: | Normal | Flags: | nattka:
sanity-check-
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [noglsa] | ||
Package list: |
=media-gfx/imagemagick-6.9.11.1 amd64 arm hppa ppc ppc64 sparc x86
=media-gfx/imagemagick-7.0.10.1 amd64 arm arm64 hppa ppc ppc64 sparc x86
=media-gfx/potrace-1.15 arm64
|
Runtime testing required: | --- |
Description
Sam James
![]() ![]() ![]() ![]() @maintainer(s), please advise if ready for stabilisation, or call yourself. Ok a month has gone by... lets try again. Are we ready to stabilize? Sanity check failed:
> media-gfx/imagemagick-7.0.10.1
> depend arm64 stable profile default/linux/arm64/17.0 (9 total)
> media-gfx/potrace
> rdepend arm64 stable profile default/linux/arm64/17.0 (9 total)
> media-gfx/potrace
amd64 stable x86 stable sparc stable hppa stable arm stable arm64 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=25628da87f65b59784b078ff90d184e9441673f5 commit 25628da87f65b59784b078ff90d184e9441673f5 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-04-30 22:51:17 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-04-30 22:51:30 +0000 media-gfx/imagemagick: security cleanup Bug: https://bugs.gentoo.org/714608 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> media-gfx/imagemagick/Manifest | 6 - media-gfx/imagemagick/imagemagick-6.9.11.0.ebuild | 250 -------------------- media-gfx/imagemagick/imagemagick-6.9.11.1.ebuild | 255 --------------------- media-gfx/imagemagick/imagemagick-6.9.11.3.ebuild | 255 --------------------- media-gfx/imagemagick/imagemagick-7.0.10.0.ebuild | 262 --------------------- media-gfx/imagemagick/imagemagick-7.0.10.1.ebuild | 267 ---------------------- media-gfx/imagemagick/imagemagick-7.0.10.3.ebuild | 267 ---------------------- 7 files changed, 1562 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=39b7886af40cc1b9747373dce91bae61700334b0 commit 39b7886af40cc1b9747373dce91bae61700334b0 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-04-30 22:50:23 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-04-30 22:51:29 +0000 media-gfx/imagemagick: move stable keywords Bug: https://bugs.gentoo.org/714608 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> media-gfx/imagemagick/imagemagick-6.9.11.7.ebuild | 2 +- media-gfx/imagemagick/imagemagick-7.0.10.7-r1.ebuild | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) GLSA Vote: No! Repository is clean, all done. Unable to check for sanity:
> no match for package: =media-gfx/imagemagick-6.9.11.1
Looking good on ppc. rdep rmagick-3.2.0 fails tests (bug #720202). # cat imagemagick-714608.report USE tests started on Do 30. Apr 11:09:52 CEST 2020 FEATURES=' test' USE='' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X bzip2 corefonts -cxx -djvu -fftw fontconfig fpx graphviz -hdri -jbig jpeg jpeg2k lcms -lqr -lzma openexr -openmp -pango perl -png -postscript -q32 -q8 raw -static-libs -svg -tiff truetype webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X bzip2 -corefonts cxx djvu -fftw fontconfig fpx -graphviz -hdri -jbig -jpeg jpeg2k -lcms lqr -lzma -openexr -openmp -pango -perl -png postscript q32 -q8 -raw -static-libs svg -tiff -truetype -webp wmf -xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='X bzip2 -corefonts cxx djvu fftw fontconfig fpx -graphviz hdri -jbig -jpeg -jpeg2k -lcms lqr lzma -openexr -openmp pango -perl -png -postscript q32 -q8 raw static-libs -svg tiff -truetype -webp wmf -xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X bzip2 -corefonts -cxx djvu fftw -fontconfig fpx graphviz hdri jbig jpeg -jpeg2k lcms -lqr -lzma -openexr openmp pango -perl png postscript q32 -q8 raw -static-libs svg -tiff truetype webp wmf -xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='X -bzip2 -corefonts -cxx -djvu -fftw fontconfig -fpx -graphviz hdri jbig jpeg -jpeg2k lcms lqr -lzma openexr openmp pango perl png -postscript q32 q8 raw -static-libs -svg tiff -truetype -webp wmf xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='X -bzip2 corefonts -cxx djvu fftw fontconfig -fpx graphviz hdri jbig jpeg jpeg2k -lcms lqr -lzma -openexr openmp -pango -perl png postscript q32 q8 raw -static-libs -svg tiff truetype webp wmf xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X bzip2 corefonts -cxx djvu fftw -fontconfig fpx -graphviz hdri -jbig -jpeg jpeg2k lcms lqr -lzma openexr openmp pango perl png postscript q32 q8 -raw static-libs svg tiff truetype webp wmf xml -zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X -bzip2 corefonts -cxx djvu -fftw -fontconfig fpx graphviz hdri jbig jpeg jpeg2k lcms lqr -lzma -openexr openmp -pango perl -png -postscript -q32 -q8 raw static-libs -svg -tiff truetype -webp wmf -xml zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X -bzip2 -corefonts cxx djvu -fftw fontconfig -fpx graphviz -hdri jbig -jpeg jpeg2k -lcms lqr lzma -openexr openmp -pango perl png -postscript q32 q8 raw -static-libs svg -tiff truetype -webp -wmf xml zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='-X bzip2 -corefonts -cxx -djvu fftw -fontconfig -fpx -graphviz -hdri -jbig -jpeg -jpeg2k lcms lqr lzma openexr openmp pango -perl png postscript q32 -q8 raw static-libs svg tiff truetype -webp -wmf xml zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='X -bzip2 -corefonts -cxx -djvu fftw fontconfig -fpx -graphviz -hdri jbig -jpeg jpeg2k -lcms lqr -lzma -openexr openmp pango perl -png postscript -q32 -q8 -raw -static-libs svg -tiff -truetype -webp wmf xml zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 USE='X -bzip2 corefonts cxx djvu -fftw -fontconfig -fpx -graphviz hdri -jbig -jpeg jpeg2k -lcms -lqr -lzma openexr -openmp -pango perl png -postscript -q32 -q8 raw -static-libs -svg tiff truetype webp wmf xml zlib' succeeded for =media-gfx/imagemagick-6.9.11.1 FEATURES=' test' USE='' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X bzip2 -corefonts cxx djvu -fftw fontconfig -fpx graphviz -hdri jbig jpeg -jpeg2k -lcms lqr -lzma openexr openmp -pango -perl -png -postscript q32 -q8 raw -static-libs -svg -tiff truetype -webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X bzip2 -corefonts -cxx -djvu fftw -fontconfig fpx -graphviz -hdri jbig -jpeg -jpeg2k lcms lqr -lzma openexr -openmp pango -perl -png -postscript q32 -q8 raw -static-libs svg tiff truetype -webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X -bzip2 corefonts -cxx -djvu -fftw -fontconfig fpx -graphviz -hdri -jbig -jpeg jpeg2k -lcms -lqr lzma -openexr openmp pango -perl -png postscript -q32 q8 raw static-libs svg tiff truetype -webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X bzip2 -corefonts -cxx djvu fftw -fontconfig -fpx graphviz hdri -jbig -jpeg jpeg2k -lcms -lqr -lzma -openexr -openmp pango -perl png -postscript q32 -q8 -raw -static-libs svg -tiff truetype webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X bzip2 -corefonts -cxx -djvu -fftw fontconfig -fpx -graphviz -hdri jbig jpeg -jpeg2k -lcms lqr lzma -openexr openmp -pango perl -png postscript -q32 q8 raw static-libs svg -tiff truetype webp -wmf -xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='-X -bzip2 -corefonts cxx -djvu fftw fontconfig fpx graphviz hdri -jbig jpeg jpeg2k -lcms lqr -lzma -openexr -openmp pango -perl -png postscript -q32 q8 -raw -static-libs -svg -tiff -truetype webp -wmf xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X -bzip2 -corefonts cxx -djvu -fftw -fontconfig -fpx -graphviz hdri jbig jpeg -jpeg2k lcms -lqr -lzma openexr openmp -pango -perl -png -postscript -q32 -q8 -raw static-libs svg -tiff truetype webp -wmf xml -zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X bzip2 corefonts -cxx djvu fftw fontconfig -fpx graphviz -hdri jbig -jpeg -jpeg2k -lcms lqr lzma -openexr -openmp pango perl png postscript q32 -q8 raw -static-libs svg tiff truetype -webp -wmf -xml zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='-X bzip2 corefonts cxx -djvu fftw fontconfig -fpx -graphviz -hdri jbig -jpeg -jpeg2k -lcms lqr lzma -openexr -openmp pango perl -png postscript q32 -q8 raw static-libs svg tiff truetype webp -wmf -xml zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X -bzip2 -corefonts -cxx djvu -fftw -fontconfig -fpx graphviz hdri -jbig jpeg -jpeg2k lcms -lqr -lzma -openexr openmp -pango perl -png -postscript -q32 q8 -raw static-libs -svg tiff truetype webp -wmf xml zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='X -bzip2 corefonts cxx -djvu fftw fontconfig -fpx -graphviz -hdri jbig jpeg -jpeg2k -lcms -lqr -lzma openexr -openmp -pango perl png postscript -q32 -q8 -raw static-libs svg tiff truetype webp -wmf xml zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 USE='-X bzip2 -corefonts cxx -djvu fftw -fontconfig -fpx -graphviz hdri -jbig -jpeg -jpeg2k lcms lqr -lzma openexr openmp -pango -perl png postscript -q32 q8 raw -static-libs -svg -tiff -truetype webp wmf xml zlib' succeeded for =media-gfx/imagemagick-7.0.10.1 revdep tests started on Do 30. Apr 16:35:41 CEST 2020 FEATURES=' test' USE='imagemagick' succeeded for media-video/dvdauthor FEATURES=' test' USE='' succeeded for dev-tex/latex2rtf FEATURES=' test' USE='imagemagick' succeeded for media-gfx/pstoedit FEATURES=' test' USE='imagemagick' succeeded for x11-wm/windowmaker FEATURES=' test' failed for dev-ruby/rmagick FEATURES=' test' USE='imagemagick' succeeded for x11-misc/xlockmore FEATURES=' test' USE='' succeeded for virtual/imagemagick-tools FEATURES=' test' USE='' succeeded for media-gfx/uniconvertor FEATURES=' test' USE='-graphicsmagick imagemagick' succeeded for media-gfx/inkscape FEATURES=' test' USE='imagemagick' succeeded for media-video/transcode FEATURES=' test' USE='imagemagick' succeeded for media-gfx/pstoedit FEATURES=' test' USE='imagemagick' succeeded for x11-misc/xlockmore FEATURES=' test' USE='' succeeded for dev-tex/tex4ht FEATURES=' test' USE='X imagemagick' succeeded for app-editors/emacs FEATURES=' test' USE='' succeeded for x11-plugins/wmgrabimage FEATURES=' test' USE='' succeeded for dev-tex/latex2rtf FEATURES=' test' USE='-graphicsmagick imagemagick' succeeded for media-gfx/inkscape FEATURES=' test' USE='imagemagick' succeeded for x11-wm/windowmaker FEATURES=' test' USE='' succeeded for media-gfx/uniconvertor FEATURES=' test' USE='' succeeded for x11-misc/rss-glx |