Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 633364 (CVE-2017-14994) - <media-gfx/graphicsmagick-1.3.27: NULL Pointer Dereference in DICOM Decoder (CVE-2017-14994)
Summary: <media-gfx/graphicsmagick-1.3.27: NULL Pointer Dereference in DICOM Decoder (...
Status: RESOLVED FIXED
Alias: CVE-2017-14994
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-03 10:08 UTC by Agostino Sarubbo
Modified: 2018-03-26 01:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-10-03 10:08:48 UTC
From ${URL} :


A null pointer dereference vulnerability in the GraphicsMagick DICOM image
decoder allows an attacker to cause a denial-of-service condition or other
unspecified impact.

Bug: https://sourceforge.net/p/graphicsmagick/bugs/512/
Writeup: https://nandynarwhals.org/CVE-2017-14994/

Timeline:
30 Sept 2017 - Discovery of the vulnerability.
1 Oct 2017 - Disclosure of vulnerability to the vendor.
1 Oct 2017 - Vulnerability fixed in mercurial commit.
2 Oct 2017 - CVE number requested.
3 Oct 2017 - CVE-2017-14994 assigned.
3 Oct 2017 - Advisory sent to oss-security mailing list.

This issue was discovered by Terry Chia (Ayrx) and Jeremy Heng (@...amon).


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-03-26 01:22:35 UTC
2017-10-03  Bob Friesenhahn  <bfriesen@simple.dallas.tx.us>

        * coders/dcm.c (DCM_ReadNonNativeImages): Additional fix
        (improvement) for SourceForge issue #512 "NULL Pointer Dereference
        in DICOM Decoder".
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-03-26 01:43:37 UTC
cleanup will be tracked in bug #640690

GLSA Vote: No