Bug 1167623 - (CVE-2020-10938) VUL-1: CVE-2020-10938: GraphicsMagick: integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c
(CVE-2020-10938)
VUL-1: CVE-2020-10938: GraphicsMagick: integer overflow and resultant heap-ba...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/255798/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-03-25 07:29 UTC by Wolfgang Frisch
Modified: 2020-05-04 12:16 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
GraphicsMagick-CVE-2020-10938.patch (6.20 KB, patch)
2020-03-25 07:46 UTC, Wolfgang Frisch
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-03-25 07:29:27 UTC
CVE-2020-10938

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based
buffer overflow in HuffmanDecodeImage in magick/compress.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-10938
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10938
https://sourceforge.net/p/graphicsmagick/code/ci/5b4dd7c6674140a115ec9424c8d19c6a458fac3e/
Comment 1 Wolfgang Frisch 2020-03-25 07:46:21 UTC
Created attachment 833813 [details]
GraphicsMagick-CVE-2020-10938.patch

Fixed by commit 95abc2b694ceb0866f8aae94849bdf4033272035

2019-11-16  Bob Friesenhahn  <bfriesen@simple.dallas.tx.us>

    * magick/compress.c (HuffmanDecodeImage): Fix signed overflow on
    range check which leads to heap overflow in 32-bit
    applications. Requires a relatively large file input compared with
    typical fuzzer files (greater than a megabyte) to trigger.
    Problem reported to the graphicsmagick-security mail address by
    Justin Tripp on 2019-11-13.
Comment 2 Petr Gajdos 2020-03-25 12:53:37 UTC
15.2: sr#788191
Comment 3 Petr Gajdos 2020-03-25 13:58:22 UTC
Package submitted to 15.1/GraphicsMagick.
I believe all fixed.
Comment 4 Swamp Workflow Management 2020-03-25 14:30:13 UTC
This is an autogenerated message for OBS integration:
This bug (1167623) was mentioned in
https://build.opensuse.org/request/show/788214 15.1 / GraphicsMagick
Comment 5 Swamp Workflow Management 2020-03-31 04:13:45 UTC
openSUSE-SU-2020:0416-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1167208,1167623
CVE References: CVE-2019-12921,CVE-2020-10938
Sources used:
openSUSE Leap 15.1 (src):    GraphicsMagick-1.3.29-lp151.4.17.1
Comment 6 Swamp Workflow Management 2020-03-31 16:22:15 UTC
openSUSE-SU-2020:0429-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1167208,1167623
CVE References: CVE-2019-12921,CVE-2020-10938
Sources used:
openSUSE Backports SLE-15-SP1 (src):    GraphicsMagick-1.3.29-bp151.5.12.1
Comment 7 Alexandros Toptsoglou 2020-05-04 12:16:02 UTC
Done