Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 611356 (CVE-2017-6335) - [TRACKER] Heap out-of-bounds read in tiff.c
Summary: [TRACKER] Heap out-of-bounds read in tiff.c
Alias: CVE-2017-6335
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Keywords: Tracker
Depends on: 611358 611360
  Show dependency tree
Reported: 2017-03-02 00:18 UTC by Thomas Deutschmann
Modified: 2018-03-27 02:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann gentoo-dev 2017-03-02 00:18:50 UTC
ImageMagick and GraphicsMagick encounter a read beyond an allocated heap buffer when reading CMYKA TIFF files which claim to offer fewer samples per pixel than required. A maliciously crafted file could cause the application to crash.


Upstream patch:
Comment 1 Aaron Bauman Gentoo Infrastructure gentoo-dev Security 2018-03-27 02:23:13 UTC
All dependent bugs fixed.