Bug 18210 - imlib2 new security issue CVE-2016-4024
Summary: imlib2 new security issue CVE-2016-4024
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/684748/
Whiteboard: has_procedure advisory MGA5-64-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-04-15 20:35 CEST by David Walser
Modified: 2016-04-22 18:34 CEST (History)
2 users (show)

See Also:
Source RPM: imlib2-1.4.8-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-04-15 20:35:00 CEST
A CVE has been assigned for another security issue fixed upstream in imlib2:
http://openwall.com/lists/oss-security/2016/04/14/8

Patched packages uploaded for Mageia 5 and Cauldron.

Advisory:
========================

Updated imlib2 packages fix security vulnerability:

Integer overflow in imlib2 1.4.8 on 32-bit machines leads to insufficient heap allocation and heap overwrite in many image loaders, potentially resulting in
remote code execution (CVE-2016-4024).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4024
http://openwall.com/lists/oss-security/2016/04/14/8
========================

Updated packages in core/updates_testing:
========================
libimlib2_1-1.4.8-1.1.mga5
libimlib2-devel-1.4.8-1.1.mga5
libimlib2_1-filters-1.4.8-1.1.mga5
libimlib2_1-loaders-1.4.8-1.1.mga5
imlib2-data-1.4.8-1.1.mga5

from imlib2-1.4.8-1.1.mga5.src.rpm
Comment 1 Len Lawrence 2016-04-18 00:23:29 CEST
x86_64  Mate

Most of the packages were already installed.
Tried out a few applications from the list provided by 
$ urpmq --whatrequires | sort |uniq

qiv         image viewer
sxiv        image viewer
deadbeef    audio player
scrot       screen capture
feh         image viewer
eterm       terminal
wmcoincoin  French talk program : pinnipede teletype
            coin coin is equivalent to quack quack
            It revealed the news that Stallman is pregnant!

They all seemed to work OK.
After updating they all continued to work as expected.

CC: (none) => tarazed25

Len Lawrence 2016-04-18 00:23:46 CEST

Whiteboard: (none) => MGA5-64-OK

Comment 2 Len Lawrence 2016-04-18 13:14:43 CEST
i586 in virtualbox  Mate

Installed the applications listed above and ran them after the update.  All function OK.

Validating this update.
Len Lawrence 2016-04-18 13:15:09 CEST

Keywords: (none) => validated_update
Whiteboard: MGA5-64-OK => MGA5-64-OK MGA5-32-OK
CC: (none) => sysadmin-bugs

Comment 3 claire robinson 2016-04-19 10:22:19 CEST
Advisory uploaded.

Whiteboard: MGA5-64-OK MGA5-32-OK => has_procedure advisory MGA5-64-OK MGA5-32-OK

Comment 4 Mageia Robot 2016-04-21 16:53:12 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0144.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2016-04-22 18:34:13 CEST

URL: (none) => http://lwn.net/Vulnerabilities/684748/


Note You need to log in before you can comment on or make changes to this bug.