Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 611356 (CVE-2017-6335) - [TRACKER] Heap out-of-bounds read in tiff.c
Summary: [TRACKER] Heap out-of-bounds read in tiff.c
Status: RESOLVED FIXED
Alias: CVE-2017-6335
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://seclists.org/oss-sec/2017/q1/494
Whiteboard:
Keywords: Tracker
Depends on: 611358 611360
Blocks:
  Show dependency tree
 
Reported: 2017-03-02 00:18 UTC by Thomas Deutschmann (RETIRED)
Modified: 2018-03-27 02:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-02 00:18:50 UTC
ImageMagick and GraphicsMagick encounter a read beyond an allocated heap buffer when reading CMYKA TIFF files which claim to offer fewer samples per pixel than required. A maliciously crafted file could cause the application to crash.

References:

http://seclists.org/oss-sec/2017/q1/494

Upstream patch:

https://sourceforge.net/p/graphicsmagick/code/ci/6156b4c2992d855ece6079653b3b93c3229fc4b8/
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-03-27 02:23:13 UTC
All dependent bugs fixed.