Bug 21004 - libraw new security issues CVE-2017-688[679] and CVE-2017-6890
Summary: libraw new security issues CVE-2017-688[679] and CVE-2017-6890
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5-32-OK advisory
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-01 12:21 CEST by David Walser
Modified: 2017-07-25 09:34 CEST (History)
3 users (show)

See Also:
Source RPM: libraw-0.16.2-1.1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-06-01 12:21:35 CEST
openSUSE has issued an advisory on May 31:
https://lists.opensuse.org/opensuse-updates/2017-05/msg00111.html

The issues were fixed upstream in 0.18.2 (already in Cauldron).
Comment 1 Marja van Waes 2017-06-01 21:18:03 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.
Comment 2 David Walser 2017-07-09 00:48:16 CEST
Patched package uploaded for Mageia 5.

Advisory:
========================

Updated libraw packages fix security vulnerabilities:

A memory corruption in parse_tiff_ifd() function (CVE-2017-6886).

A memory corruption via e.g. a specially crafted KDC file parse_tiff_ifd()
(CVE-2017-6887).

An integer overflow error within the "foveon_load_camf()" function
(CVE-2017-6889).

A boundary error within the "foveon_load_camf()" function (CVE-2017-6890).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6886
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6887
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6889
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6890
https://lists.opensuse.org/opensuse-updates/2017-05/msg00111.html
========================

Updated packages in core/updates_testing:
========================
libraw-tools-0.16.2-1.2.mga5
libraw10-0.16.2-1.2.mga5
libraw_r10-0.16.2-1.2.mga5
libraw-devel-0.16.2-1.2.mga5

from libraw-0.16.2-1.2.mga5.src.rpm
Comment 3 Herman Viaene 2017-07-24 16:16:08 CEST
MGA5-32 on Asus A6000VM Xfce
No installation issues.
Used a few raw pictures.
At CLI:
$ raw-identify P7212389.ORF 
P7212389.ORF is a Olympus E-500 image.
and
$ strace -o libraw.txt nomacs P7212389.ORF 
libpng warning: iCCP: known incorrect sRGB profile
libpng warning: iCCP: known incorrect sRGB profile
libpng warning: iCCP: known incorrect sRGB profile
libpng warning: iCCP: known incorrect sRGB profile
new suffix: .jpg *.jpeg)
I could save the image...
Resulting jpg file OK.

Note You need to log in before you can comment on or make changes to this bug.