Bug 1219821 (CVE-2024-25445)

Summary: VUL-0: CVE-2024-25445: hugin: assertion failure in HuginBase::PTools::Transform::transform
Product: [openSUSE] openSUSE Distribution Reporter: SMASH SMASH <smash_bz>
Component: SecurityAssignee: Security Team bot <security-team>
Status: NEW --- QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: thomas.leroy
Version: Leap 15.6   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/393581/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description SMASH SMASH 2024-02-12 09:45:58 UTC
Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25445
https://bugs.launchpad.net/hugin/+bug/2025038
https://www.cve.org/CVERecord?id=CVE-2024-25445
https://bugzilla.redhat.com/show_bug.cgi?id=2263555
Comment 1 Petr Gajdos 2024-02-13 13:29:21 UTC
Not sure about correct reproducing command, I get however:

2022.0.0
$ valgrind  -q pto_merge poc-file.txt poc-file.txt

Written output to poc-file_merge.pto
$

2023.0.0
:/219821 # pto_merge poc-file.txt poc-file.txt
file "poc-file.txt" seems to be an image file and not a PTO file.
:/219821 #

Upstream bug suggests the issue was fixed in Hugin 2023.0beta1.
Comment 2 OBSbugzilla Bot 2024-02-13 14:25:03 UTC
This is an autogenerated message for OBS integration:
This bug (1219821) was mentioned in
https://build.opensuse.org/request/show/1146413 Backports:SLE-15-SP5 / hugin
Comment 3 Petr Gajdos 2024-02-14 13:22:16 UTC
Submitted a version update (-> 2023.0.0) for b15sp6 and b15sp5.

I believe all fixed.
Comment 4 OBSbugzilla Bot 2024-02-14 13:55:04 UTC
This is an autogenerated message for OBS integration:
This bug (1219821) was mentioned in
https://build.opensuse.org/request/show/1146570 Factory / hugin
https://build.opensuse.org/request/show/1146575 Backports:SLE-15-SP6 / hugin
Comment 5 Marcus Meissner 2024-02-14 17:05:03 UTC
openSUSE-SU-2024:0047-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1219819,1219820,1219821,1219822
CVE References: CVE-2024-25442,CVE-2024-25443,CVE-2024-25445,CVE-2024-25446
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    hugin-2023.0.0-bp155.2.3.1