Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 890851

Summary: <media-gfx/graphicsmagick-1.3.40: Multiple vulnerabilities
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: IN_PROGRESS ---    
Severity: normal CC: codec, sam
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [glsa?]
Package list:
Runtime testing required: ---
Bug Depends on: 894484    
Bug Blocks:    

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-01-14 23:14:59 UTC
As usual, assortment of oss-fuzz fixes (no specific citations given), but also:
```
 42 +Security Fixes:
 43 +
 44 +* DCX: Fixed heap overflow when writing more than 1023 scenes, and
 45 +  also eliminated use of uninitialized memory.
 46 +
```
Comment 1 Larry the Git Cow gentoo-dev 2023-01-14 23:22:26 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=347517dffa9f98c921535211bbe57aaa96c7d7d3

commit 347517dffa9f98c921535211bbe57aaa96c7d7d3
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-14 23:13:57 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-14 23:15:07 +0000

    media-gfx/graphicsmagick: add 1.3.40
    
    Bug: https://bugs.gentoo.org/890851
    Signed-off-by: Sam James <sam@gentoo.org>

 media-gfx/graphicsmagick/Manifest                  |   2 +
 .../graphicsmagick/graphicsmagick-1.3.40.ebuild    | 160 +++++++++++++++++++++
 2 files changed, 162 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2023-03-09 06:41:34 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a80a21a605475095d050ea14833d354338fc9e86

commit a80a21a605475095d050ea14833d354338fc9e86
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-03-09 06:41:18 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-03-09 06:41:18 +0000

    media-gfx/graphicsmagick: drop 1.3.38-r5, 1.3.39
    
    Bug: https://bugs.gentoo.org/888545
    Bug: https://bugs.gentoo.org/890851
    Signed-off-by: Sam James <sam@gentoo.org>

 media-gfx/graphicsmagick/Manifest                  |   4 -
 .../graphicsmagick-1.3.38-configure-bashism.patch  |  34 -----
 .../graphicsmagick/graphicsmagick-1.3.38-r5.ebuild | 161 ---------------------
 .../graphicsmagick/graphicsmagick-1.3.39.ebuild    | 160 --------------------
 4 files changed, 359 deletions(-)