Bug 1216403 (CVE-2023-46009) - VUL-0: CVE-2023-46009: gifsicle: floating point exception vulnerability via resize_stream at src/xform.c
Summary: VUL-0: CVE-2023-46009: gifsicle: floating point exception vulnerability via r...
Status: RESOLVED FIXED
Alias: CVE-2023-46009
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Manfred Schwarb
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/382359/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-19 07:40 UTC by SMASH SMASH
Modified: 2024-06-27 23:00 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-10-19 07:40:58 UTC
gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46009
Comment 1 Gabriele Sonnu 2023-10-19 07:42:48 UTC
Tracking as affected:

- openSUSE:Backports:SLE-15-SP4/gifsicle  (v1.93)
- openSUSE:Backports:SLE-15-SP5/gifsicle  (v1.93)
- openSUSE:Factory/gifsicle  (v1.94)

Upstream issue:

https://github.com/kohler/gifsicle/issues/196

Upstream fixes:

https://github.com/kohler/gifsicle/commit/06d533628b1f3a75d06cbb29773dc6aaa2916fc3
https://github.com/kohler/gifsicle/commit/76b1f021dd185ceff7b4a71a9f96a6026aca06af
Comment 2 Manfred Schwarb 2024-03-03 00:06:11 UTC
This is fixed in gifsicle 1.95, which has been incorporated in
- openSUSE:Backports:SLE-15-SP6
- openSUSE:Factory
Comment 3 Andreas Stieger 2024-05-28 21:38:39 UTC
Reopening: Missing in Leap 15.6. Please process incoming submission or fix in Leap 15.6 in your chosen way. (bug 1225537)
Comment 4 Manfred Schwarb 2024-05-28 23:42:26 UTC
Hmm, there was
  https://build.opensuse.org/request/show/1152098
and so the version 1.95 does appear in the in the "Inherited packages"
section of
  https://build.opensuse.org/project/show/openSUSE:Leap:15.6#tab-pane-inherited-packages

I'm surprised that version 1.95 should be missing in Leap 15.6 ?
Comment 5 Manfred Schwarb 2024-05-28 23:50:54 UTC
Or do you mean Leap 15.5?
Yes, I did no maintenance request for Leap 15.5, as the mentioned bug
seemed not terribly crucial to me. But backporting would be fine by me.
Comment 6 Andreas Stieger 2024-05-29 04:02:24 UTC
Yes sorry the diff was reversed. Missing in 15.5.
https://build.opensuse.org/request/show/1177406
Comment 7 Marcus Meissner 2024-05-29 22:05:11 UTC
openSUSE-SU-2024:0146-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1216403
CVE References: CVE-2023-46009
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    gifsicle-1.95-bp155.3.6.1
Comment 8 Manfred Schwarb 2024-06-27 23:00:29 UTC
Leap 15.5 is fixed now as well, so we can close this bug.