Bug 815382 - VUL-0: CVE-2013-1953: autotrace: stack-based buffer overflow in bmp parser
VUL-0: CVE-2013-1953: autotrace: stack-based buffer overflow in bmp parser
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-04-16 08:30 UTC by Sebastian Krahmer
Modified: 2013-06-19 09:36 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
CVE-2013-1953.patch (589 bytes, patch)
2013-05-28 15:29 UTC, Stanislav Brabec
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Sebastian Krahmer 2013-04-16 08:34:36 UTC
Do we need an extra gimp bug? The commit that fixes it, seems to be quite old.
Comment 2 Sebastian Krahmer 2013-04-16 09:06:34 UTC
CVE-2013-1953
Comment 3 Swamp Workflow Management 2013-04-16 22:00:08 UTC
bugbot adjusting priority
Comment 4 Stanislav Brabec 2013-05-28 15:29:28 UTC
Created attachment 541559 [details]
CVE-2013-1953.patch

If I understand correctly, the whole security fix is the attached oneliner.
Comment 5 Stanislav Brabec 2013-05-28 17:57:56 UTC
Created maintenance request id 176883 for openSUSE.

The package seems to not exist in SLE.
Comment 6 Bernhard Wiedemann 2013-06-06 05:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (815382) was mentioned in
https://build.opensuse.org/request/show/177885 Evergreen:11.2 / autotrace
Comment 7 Swamp Workflow Management 2013-06-19 04:04:21 UTC
openSUSE-SU-2013:1044-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 815382
CVE References: CVE-2013-1953
Sources used:
openSUSE 12.3 (src):    autotrace-0.31.1-637.4.1
openSUSE 12.2 (src):    autotrace-0.31.1-635.4.1
Comment 8 Swamp Workflow Management 2013-06-19 05:04:35 UTC
openSUSE-SU-2013:1049-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 815382
CVE References: CVE-2013-1953
Sources used:
openSUSE 11.4 (src):    autotrace-0.31.1-629.1
Comment 9 Marcus Meissner 2013-06-19 09:36:00 UTC
released