Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 727444 (CVE-2020-13902)

Summary: <media-gfx/imagemagick-{6.9.11.19,7.0.10.19}: Multiple vulnerabilities (CVE-2020-13902)
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: dilfridge
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20920
See Also: https://bugs.gentoo.org/show_bug.cgi?id=718948
https://bugs.gentoo.org/show_bug.cgi?id=727718
Whiteboard: B3 [noglsa cve]
Package list:
Runtime testing required: ---

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-07 17:52:10 UTC
Description:
"ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-11 23:21:11 UTC
*** Bug 727718 has been marked as a duplicate of this bug. ***
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-11 23:22:17 UTC
Also:
* Null pointer dereference when handling TIFF images.

https://github.com/ImageMagick/ImageMagick/commit/ad86bdfef9e22db10d54e5d414f7d44cf13a6e95, fixed in -18
* Various other oss-fuzz fixes in -18.