Bug 21680 - gdk-pixbuf2.0 new security issues CVE-2017-2862 CVE-2017-2870 CVE-2017-6312 CVE-2017-6313 CVE-2017-6314
Summary: gdk-pixbuf2.0 new security issues CVE-2017-2862 CVE-2017-2870 CVE-2017-6312 C...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5TOO MGA5-32-OK MGA5-64-OK
Keywords: advisory, validated_update
: 25904 (view as bug list)
Depends on:
Blocks:
 
Reported: 2017-09-07 15:14 CEST by David Walser
Modified: 2019-12-20 12:18 CET (History)
5 users (show)

See Also:
Source RPM: gdk-pixbuf2.0-2.36.7-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-09-07 15:14:50 CEST
SUSE has issued an advisory on September 6:
https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00015.html

Mageia 5 is probably also affected.

It doesn't look like fixes for most of these have been committed upstream yet.
David Walser 2017-09-07 15:14:57 CEST

Whiteboard: (none) => MGA5TOO

Comment 1 Marja Van Waes 2017-09-08 00:16:56 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

Assignee: bugsquad => pkg-bugs
CC: (none) => marja11

Comment 2 David Walser 2017-09-11 20:39:43 CEST
openSUSE has issued an advisory for this on September 8:
https://lists.opensuse.org/opensuse-updates/2017-09/msg00031.html
Comment 3 David Walser 2017-09-18 23:09:23 CEST
There is also CVE-2017-6311 from this Ubuntu advisory from today (September 18):
https://usn.ubuntu.com/usn/usn-3418-1/
Comment 4 David Walser 2017-12-28 22:06:33 CET
Mageia 6 already had the commits for CVE-2017-2862, CVE-2017-2870, and CVE-2017-6311 in 2.36.10.
Comment 5 David Walser 2017-12-28 22:25:47 CET
Advisory:
========================

Updated gdk-pixbuf2.0 packages fix security vulnerabilities:

JPEG gdk_pixbuf__jpeg_image_load_increment Code Execution Vulnerability
(CVE-2017-2862).

tiff_image_parse Code Execution Vulnerability (CVE-2017-2870).

Ariel Zelivansky discovered that the GDK-PixBuf library did not properly
handle printing certain error messages. If an user or automated system were
tricked into opening a specially crafted image file, a remote attacker
could use this flaw to cause GDK-PixBuf to crash, resulting in a denial of
service (CVE-2017-6311).

Out-of-bounds read on io-ico.c (CVE-2017-6312).

A dangerous integer underflow in io-icns.c (CVE-2017-6313).

Infinite loop in io-tiff.c (CVE-2017-6314).

Note, the CVE-2017-2862, CVE-2017-2870, and CVE-2017-6311 issues only affected
Mageia 5.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2862
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2870
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6311
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6312
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6313
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6314
https://usn.ubuntu.com/usn/usn-3418-1/
https://lists.opensuse.org/opensuse-updates/2017-09/msg00031.html
========================

Updated packages in core/updates_testing:
========================
gdk-pixbuf2.0-2.32.3-1.1.mga5
libgdk_pixbuf2.0_0-2.32.3-1.1.mga5
libgdk_pixbuf2.0-devel-2.32.3-1.1.mga5
libgdk_pixbuf-gir2.0-2.32.3-1.1.mga5
gdk-pixbuf2.0-2.36.10-1.1.mga6
libgdk_pixbuf2.0_0-2.36.10-1.1.mga6
libgdk_pixbuf2.0-devel-2.36.10-1.1.mga6
libgdk_pixbuf-gir2.0-2.36.10-1.1.mga6

from SRPMS:
gdk-pixbuf2.0-2.32.3-1.1.mga5.src.rpm
gdk-pixbuf2.0-2.36.10-1.1.mga6.src.rpm

Assignee: pkg-bugs => qa-bugs

Comment 6 Lewis Smith 2017-12-30 12:02:12 CET
To prioritise.
Comment 7 Herman Viaene 2017-12-31 12:00:19 CET
MGA5-32 on Dell Latitude D600 Xfce
No installation issues
Ref to bug 21658 Comment 7 for at test
$ convert 1973.jpg -colorspace Gray grayslide1.jpg
produces a perfect grayslide viewed in ristretto.

CC: (none) => herman.viaene
Whiteboard: MGA5TOO => MGA5TOO MGA5-32-OK

Dave Hodgins 2018-01-01 07:30:59 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 8 Dave Hodgins 2018-01-01 11:16:45 CET
Similar testing on MGA5 x86_64.

Validating the update.

Keywords: (none) => validated_update
Whiteboard: MGA5TOO MGA5-32-OK => MGA5TOO MGA5-32-OK MGA5-64-OK
CC: (none) => sysadmin-bugs

Comment 9 Mageia Robot 2018-01-01 16:51:29 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0016.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 10 David Walser 2019-12-20 12:18:47 CET
*** Bug 25904 has been marked as a duplicate of this bug. ***

CC: (none) => zombie.ryushu


Note You need to log in before you can comment on or make changes to this bug.