Mageia Bugzilla – Attachment 9527 Details for
Bug 19668
graphicsmagick several (possible) new security issues
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
Log In
[x]
|
New Account
|
Forgot Password
List of test results for the reproducers before the updates
before (text/plain), 5.47 KB, created by
Len Lawrence
on 2017-07-28 17:26:51 CEST
(
hide
)
Description:
List of test results for the reproducers before the updates
Filename:
MIME Type:
Creator:
Len Lawrence
Created:
2017-07-28 17:26:51 CEST
Size:
5.47 KB
patch
obsolete
>In several cases the identify function returned data which could be displayed as a valid image. > >$ gm identify 4a1d6a6d >gm identify: Improper image header (4a1d6a6d). >gm identify: Request did not return an image. > >$ gm identify 68e4a715 >gm identify: Improper image header (68e4a715). >gm identify: Request did not return an image. >$ gm convert 68e4a715 test.bmp >gm convert: Improper image header (68e4a715). > >$ gm identify imagemagick-heapoverflow-SetPixelIndex.wpg >gm identify: Memory allocation failed (imagemagick-heapoverflow-SetPixelIndex.wpg). >gm identify: Request did not return an image. >$ gm identify imagemagick-invalid-write-ScaleCharToQuantum.wpg >gm identify: Memory allocation failed (imagemagick-invalid-write-ScaleCharToQuantum.wpg). >gm identify: Request did not return an image. >$ gm identify imagemagick-invalid-write-SetPixelIndex.wpg >gm identify: Memory allocation failed (imagemagick-invalid-write-SetPixelIndex.wpg). >gm identify: Request did not return an image. > >$ gm identify CVE-2016-6823.ppm >gm identify: Unexpected end-of-file (CVE-2016-6823.ppm). >gm identify: Request did not return an image. > >$ gm identify CVE-2016-7101.sgi >gm identify: Improper image header (CVE-2016-7101.sgi). >gm identify: Request did not return an image. > >$ gm identify id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10 >gm identify: Memory allocation failed (id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10). >gm identify: Request did not return an image. > >$ gm identify id_000071,sig_06,src_002008,op_flip1,pos_580 >gm identify: Memory allocation failed (id_000071,sig_06,src_002008,op_flip1,pos_580). >gm identify: Request did not return an image. > >$ gm identify id_000045,sig_06,src_001710,op_int16,pos_562,val_+32 >gm identify: Memory allocation failed (id_000045,sig_06,src_001710,op_int16,pos_562,val_+32). >gm identify: Request did not return an image. > >$ gm identify id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10 >gm identify: Memory allocation failed (id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10). >gm identify: Request did not return an image. > >$ gm identify id_000125,sig_06,src_003820,op_havoc,rep_2 >gm identify: No decode delegate for this image format (id_000125,sig_06,src_003820,op_havoc,rep_2). >gm identify: Request did not return an image. > >$ gm identify id_000147,sig_06,src_004628,op_havoc,rep_128 >id_000147,sig_06,src_004628,op_havoc,rep_128 8BIMTEXT 1x1+0+0 DirectClass 8-bit 10.0Ki 0.000u 0m:0.000001s > >$ gm identify id_000002,sig_06,src_000001,op_flip1,pos_866 >id_000002,sig_06,src_000001,op_flip1,pos_866 WPG 200x16+0+0 PseudoClass 256c 8-bit 971 0.000u 0m:0.000001s > >$ gm identify id_000004,sig_06,src_000001,op_int8,pos_864,val_+1 >id_000004,sig_06,src_000001,op_int8,pos_864,val_+1 WPG 1x144+0+0 PseudoClass 256c 8-bit 971 0.000u 0m:0.000002s > >$ gm identify id_000081,sig_06,src_000197,op_ext_AO,pos_686 >id_000081,sig_06,src_000197,op_ext_AO,pos_686 WPG 10x144+0+0 PseudoClass 4c 8-bit 712 0.000u 0m:0.000002s > >$ gm identify id_000346,sig_06,src_005762,op_havoc,rep_32 >gm identify: Image file or blob does not contain any image data. >gm identify: Request did not return an image. > >$ gm identify id_000225,sig_06,src_000141+002191,op_splice,rep_64 >gm identify: Insufficient image data in file (id_000225,sig_06,src_000141+002191,op_splice,rep_64). >gm identify: Request did not return an image. > >$ gm identify id_000081,sig_06,src_000075,op_havoc,rep_16 >id_000081,sig_06,src_000075,op_havoc,rep_16 MAT 32x1056+0+0 DirectClass 8-bit 1.1Ki 0.000u 0m:0.000002s > >$ gm convert id_000081,sig_06,src_000075,op_havoc,rep_16 /dev/null >That worked. >$ gm convert id_000081,sig_06,src_000075,op_havoc,rep_16 dummy >$ display dummy >!Showed an image whereas the upstream test caused an abort and a stack dump. > >$ gm identify id_000012,sig_06,src_000016,op_flip1,pos_26 >gm identify: Corrupt image (Claimed tile data length is insufficient for tile data). >gm identify: Request did not return an image. > >$ gm identify id_000000,sig_06,src_000000,op_flip1,pos_119 >id_000000,sig_06,src_000000,op_flip1,pos_119 PDB 8x32+0+0 PseudoClass 2c 8-bit 204 0.000u 0m:0.000002s >$ gm identify id_000122,sig_06,src_000277,op_havoc,rep_8 >id_000122,sig_06,src_000277,op_havoc,rep_8 PDB 8x32+0+0 PseudoClass 4c 8-bit 442 0.000u 0m:0.000002s >$ gm identify id_000338,sig_06,src_005458,op_havoc,rep_8 >gm identify: Memory allocation failed (id_000338,sig_06,src_005458,op_havoc,rep_8). >gm identify: Request did not return an image. > >$ gm identify id_000419,sig_06,src_001803+004110,op_splice,rep_2 >id_000419,sig_06,src_001803+004110,op_splice,rep_2 PDB 4x30+0+0 PseudoClass 16c 8-bit 164 0.000u 0m:0.000003s > >$ gm identify 'id&%000067,sig&%06,src&%000833,op&%havoc,rep&%2' >id&%000067,sig&%06,src&%000833,op&%havoc,rep&%2 PDB 32x64+0+0 PseudoClass 16c 8-bit 272 0.000u 0m:0.000005s > >$ gm identify 00096-graphicsmagick-memalloc-MagickRealloc >gm identify: abort due to signal 7 (SIGBUS) "Bus Error"... >Aborted (core dumped) > >$ gm identify memory-leak-in-ReadJNGImage-8.jng >gm identify: Bogus Huffman table definition (/tmp/gmxMLk20). >gm identify: Request did not return an image. > >$ gm identify memory-leak-in-ReadPCDImage-9.pcd >gm identify: Improper image header (memory-leak-in-ReadPCDImage-9.pcd). >gm identify: Request did not return an image. > >$ gm identify memory-leak-in-ReadPICTImage-16.pict >gm identify: Improper image header (memory-leak-in-ReadPICTImage-16.pict). >gm identify: Request did not return an image. > >$ gm identify memory-leak-in-ReadMTVImage-11.mtv >gm identify: Unexpected end-of-file (memory-leak-in-ReadMTVImage-11.mtv). >gm identify: Request did not return an image. > > > > > > > > > >
In several cases the identify function returned data which could be displayed as a valid image. $ gm identify 4a1d6a6d gm identify: Improper image header (4a1d6a6d). gm identify: Request did not return an image. $ gm identify 68e4a715 gm identify: Improper image header (68e4a715). gm identify: Request did not return an image. $ gm convert 68e4a715 test.bmp gm convert: Improper image header (68e4a715). $ gm identify imagemagick-heapoverflow-SetPixelIndex.wpg gm identify: Memory allocation failed (imagemagick-heapoverflow-SetPixelIndex.wpg). gm identify: Request did not return an image. $ gm identify imagemagick-invalid-write-ScaleCharToQuantum.wpg gm identify: Memory allocation failed (imagemagick-invalid-write-ScaleCharToQuantum.wpg). gm identify: Request did not return an image. $ gm identify imagemagick-invalid-write-SetPixelIndex.wpg gm identify: Memory allocation failed (imagemagick-invalid-write-SetPixelIndex.wpg). gm identify: Request did not return an image. $ gm identify CVE-2016-6823.ppm gm identify: Unexpected end-of-file (CVE-2016-6823.ppm). gm identify: Request did not return an image. $ gm identify CVE-2016-7101.sgi gm identify: Improper image header (CVE-2016-7101.sgi). gm identify: Request did not return an image. $ gm identify id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10 gm identify: Memory allocation failed (id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10). gm identify: Request did not return an image. $ gm identify id_000071,sig_06,src_002008,op_flip1,pos_580 gm identify: Memory allocation failed (id_000071,sig_06,src_002008,op_flip1,pos_580). gm identify: Request did not return an image. $ gm identify id_000045,sig_06,src_001710,op_int16,pos_562,val_+32 gm identify: Memory allocation failed (id_000045,sig_06,src_001710,op_int16,pos_562,val_+32). gm identify: Request did not return an image. $ gm identify id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10 gm identify: Memory allocation failed (id_000019,sig_06,src_000452,op_arith16,pos_10,val_-10). gm identify: Request did not return an image. $ gm identify id_000125,sig_06,src_003820,op_havoc,rep_2 gm identify: No decode delegate for this image format (id_000125,sig_06,src_003820,op_havoc,rep_2). gm identify: Request did not return an image. $ gm identify id_000147,sig_06,src_004628,op_havoc,rep_128 id_000147,sig_06,src_004628,op_havoc,rep_128 8BIMTEXT 1x1+0+0 DirectClass 8-bit 10.0Ki 0.000u 0m:0.000001s $ gm identify id_000002,sig_06,src_000001,op_flip1,pos_866 id_000002,sig_06,src_000001,op_flip1,pos_866 WPG 200x16+0+0 PseudoClass 256c 8-bit 971 0.000u 0m:0.000001s $ gm identify id_000004,sig_06,src_000001,op_int8,pos_864,val_+1 id_000004,sig_06,src_000001,op_int8,pos_864,val_+1 WPG 1x144+0+0 PseudoClass 256c 8-bit 971 0.000u 0m:0.000002s $ gm identify id_000081,sig_06,src_000197,op_ext_AO,pos_686 id_000081,sig_06,src_000197,op_ext_AO,pos_686 WPG 10x144+0+0 PseudoClass 4c 8-bit 712 0.000u 0m:0.000002s $ gm identify id_000346,sig_06,src_005762,op_havoc,rep_32 gm identify: Image file or blob does not contain any image data. gm identify: Request did not return an image. $ gm identify id_000225,sig_06,src_000141+002191,op_splice,rep_64 gm identify: Insufficient image data in file (id_000225,sig_06,src_000141+002191,op_splice,rep_64). gm identify: Request did not return an image. $ gm identify id_000081,sig_06,src_000075,op_havoc,rep_16 id_000081,sig_06,src_000075,op_havoc,rep_16 MAT 32x1056+0+0 DirectClass 8-bit 1.1Ki 0.000u 0m:0.000002s $ gm convert id_000081,sig_06,src_000075,op_havoc,rep_16 /dev/null That worked. $ gm convert id_000081,sig_06,src_000075,op_havoc,rep_16 dummy $ display dummy !Showed an image whereas the upstream test caused an abort and a stack dump. $ gm identify id_000012,sig_06,src_000016,op_flip1,pos_26 gm identify: Corrupt image (Claimed tile data length is insufficient for tile data). gm identify: Request did not return an image. $ gm identify id_000000,sig_06,src_000000,op_flip1,pos_119 id_000000,sig_06,src_000000,op_flip1,pos_119 PDB 8x32+0+0 PseudoClass 2c 8-bit 204 0.000u 0m:0.000002s $ gm identify id_000122,sig_06,src_000277,op_havoc,rep_8 id_000122,sig_06,src_000277,op_havoc,rep_8 PDB 8x32+0+0 PseudoClass 4c 8-bit 442 0.000u 0m:0.000002s $ gm identify id_000338,sig_06,src_005458,op_havoc,rep_8 gm identify: Memory allocation failed (id_000338,sig_06,src_005458,op_havoc,rep_8). gm identify: Request did not return an image. $ gm identify id_000419,sig_06,src_001803+004110,op_splice,rep_2 id_000419,sig_06,src_001803+004110,op_splice,rep_2 PDB 4x30+0+0 PseudoClass 16c 8-bit 164 0.000u 0m:0.000003s $ gm identify 'id&%000067,sig&%06,src&%000833,op&%havoc,rep&%2' id&%000067,sig&%06,src&%000833,op&%havoc,rep&%2 PDB 32x64+0+0 PseudoClass 16c 8-bit 272 0.000u 0m:0.000005s $ gm identify 00096-graphicsmagick-memalloc-MagickRealloc gm identify: abort due to signal 7 (SIGBUS) "Bus Error"... Aborted (core dumped) $ gm identify memory-leak-in-ReadJNGImage-8.jng gm identify: Bogus Huffman table definition (/tmp/gmxMLk20). gm identify: Request did not return an image. $ gm identify memory-leak-in-ReadPCDImage-9.pcd gm identify: Improper image header (memory-leak-in-ReadPCDImage-9.pcd). gm identify: Request did not return an image. $ gm identify memory-leak-in-ReadPICTImage-16.pict gm identify: Improper image header (memory-leak-in-ReadPICTImage-16.pict). gm identify: Request did not return an image. $ gm identify memory-leak-in-ReadMTVImage-11.mtv gm identify: Unexpected end-of-file (memory-leak-in-ReadMTVImage-11.mtv). gm identify: Request did not return an image.
View Attachment As Raw
Actions:
View
Attachments on
bug 19668
:
9518
|
9526
| 9527 |
9528