Bug 1059663 - (CVE-2017-14532) VUL-0: CVE-2017-14532: ImageMagick: NULL Pointer Dereference in TIFFIgnoreTags incoders/tiff.c. could lead to remote denial of service
(CVE-2017-14532)
VUL-0: CVE-2017-14532: ImageMagick: NULL Pointer Dereference in TIFFIgnoreTag...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE Factory
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/192137/
CVSSv2:NVD:CVE-2017-14532:7.5:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-09-21 06:51 UTC by Victor Pereira
Modified: 2017-10-16 22:41 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Victor Pereira 2017-09-21 06:54:02 UTC
I wasn't able to find the function TIFFIgnoreTags in our enteprise codestreams. Therefore I think we are not affected. I couldn't find any reproducer.
Comment 2 Marcus Meissner 2017-09-29 10:00:05 UTC
considering sle not affected after last comment.
Comment 3 Petr Gajdos 2017-10-05 08:13:34 UTC
ImageMagick: factory has the patch already, 12 and older is not affected (comment 1)

GraphicsMagick: 12 not affected (comment 1)
                42.2, 42.3 and devel affected
                mercurial not affected (have the check already)
Comment 4 Petr Gajdos 2017-10-05 12:46:31 UTC
Packages for 42.3 and 42.2 submitted. Tumbleweed will be fixed trough version update.
Comment 5 Bernhard Wiedemann 2017-10-05 14:01:01 UTC
This is an autogenerated message for OBS integration:
This bug (1059663) was mentioned in
https://build.opensuse.org/request/show/531714 42.2 / GraphicsMagick
https://build.opensuse.org/request/show/531715 42.3 / GraphicsMagick
Comment 6 Bernhard Wiedemann 2017-10-06 14:01:21 UTC
This is an autogenerated message for OBS integration:
This bug (1059663) was mentioned in
https://build.opensuse.org/request/show/532233 42.2 / GraphicsMagick
https://build.opensuse.org/request/show/532234 42.3 / GraphicsMagick
Comment 7 Bernhard Wiedemann 2017-10-09 12:00:34 UTC
This is an autogenerated message for OBS integration:
This bug (1059663) was mentioned in
https://build.opensuse.org/request/show/532710 42.3 / GraphicsMagick
https://build.opensuse.org/request/show/532711 42.2 / GraphicsMagick
Comment 8 Andreas Stieger 2017-10-16 18:53:27 UTC
release for Leap, done
Comment 9 Swamp Workflow Management 2017-10-16 22:11:18 UTC
openSUSE-SU-2017:2735-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1059663,1061873
CVE References: CVE-2017-14532,CVE-2017-15033
Sources used:
openSUSE Leap 42.3 (src):    GraphicsMagick-1.3.25-27.1
openSUSE Leap 42.2 (src):    GraphicsMagick-1.3.25-11.27.1