Bug 1219821 (CVE-2024-25445) - VUL-0: CVE-2024-25445: hugin: assertion failure in HuginBase::PTools::Transform::transform
Summary: VUL-0: CVE-2024-25445: hugin: assertion failure in HuginBase::PTools::Transfo...
Status: NEW
Alias: CVE-2024-25445
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/393581/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-12 09:45 UTC by SMASH SMASH
Modified: 2024-02-14 17:05 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-02-12 09:45:58 UTC
Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25445
https://bugs.launchpad.net/hugin/+bug/2025038
https://www.cve.org/CVERecord?id=CVE-2024-25445
https://bugzilla.redhat.com/show_bug.cgi?id=2263555
Comment 1 Petr Gajdos 2024-02-13 13:29:21 UTC
Not sure about correct reproducing command, I get however:

2022.0.0
$ valgrind  -q pto_merge poc-file.txt poc-file.txt

Written output to poc-file_merge.pto
$

2023.0.0
:/219821 # pto_merge poc-file.txt poc-file.txt
file "poc-file.txt" seems to be an image file and not a PTO file.
:/219821 #

Upstream bug suggests the issue was fixed in Hugin 2023.0beta1.
Comment 2 OBSbugzilla Bot 2024-02-13 14:25:03 UTC
This is an autogenerated message for OBS integration:
This bug (1219821) was mentioned in
https://build.opensuse.org/request/show/1146413 Backports:SLE-15-SP5 / hugin
Comment 3 Petr Gajdos 2024-02-14 13:22:16 UTC
Submitted a version update (-> 2023.0.0) for b15sp6 and b15sp5.

I believe all fixed.
Comment 4 OBSbugzilla Bot 2024-02-14 13:55:04 UTC
This is an autogenerated message for OBS integration:
This bug (1219821) was mentioned in
https://build.opensuse.org/request/show/1146570 Factory / hugin
https://build.opensuse.org/request/show/1146575 Backports:SLE-15-SP6 / hugin
Comment 5 Marcus Meissner 2024-02-14 17:05:03 UTC
openSUSE-SU-2024:0047-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1219819,1219820,1219821,1219822
CVE References: CVE-2024-25442,CVE-2024-25443,CVE-2024-25445,CVE-2024-25446
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    hugin-2023.0.0-bp155.2.3.1