Bug 25264 - evince new security issue CVE-2019-11459
Summary: evince new security issue CVE-2019-11459
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-08-11 20:41 CEST by David Walser
Modified: 2019-12-06 15:17 CET (History)
8 users (show)

See Also:
Source RPM: evince-3.32.0-2.mga7.src.rpm
CVE: CVE-2019-11459
Status comment: Fixed upstream in 3.32.1


Attachments

Description David Walser 2019-08-11 20:41:29 CEST
Ubuntu has issued an advisory on April 29:
https://usn.ubuntu.com/3959-1/

Mageia 6 and Mageia 7 are also affected.
David Walser 2019-08-11 20:41:36 CEST

Whiteboard: (none) => MGA7TOO, MGA6TOO

Comment 1 Marja Van Waes 2019-08-11 22:24:01 CEST
Assigning to the Gnome maintainers. CC'ing a recent submitter and also the registered maintainer.

Assignee: bugsquad => gnome
CC: (none) => cvargas, geiger.david68210, marja11

Comment 2 David Walser 2019-08-12 01:10:16 CEST
Ubuntu has issued an advisory on July 22:
https://usn.ubuntu.com/4067-1/

Only Mageia 6 is affected by this issue.

Summary: evince new security issue CVE-2019-11459 => evince new security issue CVE-2019-11459 and CVE-2019-1010006

Comment 3 David Walser 2019-11-12 18:04:17 CET
Mageia 6 is EOL, removing CVE-2019-1010006 from the bug title.

The original issue is fixed upstream in 3.32.1 and 3.34.0, so Cauldron is OK.

RedHat has issued an advisory for this on November 5:
https://access.redhat.com/errata/RHSA-2019:3553

Whiteboard: MGA7TOO, MGA6TOO => (none)
Version: Cauldron => 7
Summary: evince new security issue CVE-2019-11459 and CVE-2019-1010006 => evince new security issue CVE-2019-11459
Source RPM: evince-3.32.0-3.mga8.src.rpm => evince-3.32.0-2.mga7.src.rpm
Status comment: (none) => Fixed upstream in 3.32.1

Comment 4 Nicolas Salguero 2019-11-26 09:27:08 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. (CVE-2019-11459)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11459
https://usn.ubuntu.com/3959-1/
https://access.redhat.com/errata/RHSA-2019:3553
========================

Updated packages in core/updates_testing:
========================
evince-3.32.1-1.mga7
evince-dvi-3.32.1-1.mga7
lib(64)evdocument3_4-3.32.1-1.mga7
lib(64)evview3_3-3.32.1-1.mga7
lib(64)evince-devel-3.32.1-1.mga7
lib(64)evince-gir3.0-3.32.1-1.mga7

from SRPMS:
evince-3.32.1-1.mga7.src.rpm

Assignee: gnome => qa-bugs
CVE: (none) => CVE-2019-11459
CC: (none) => nicolas.salguero
Status: NEW => ASSIGNED

Comment 5 Brian Rockwell 2019-11-26 17:45:27 CET
The following 5 packages are going to be installed:

- evince-3.32.1-1.mga7.x86_64
- glibc-2.29-19.mga7.x86_64
- lib64evdocument3_4-3.32.1-1.mga7.x86_64
- lib64evince-gir3.0-3.32.1-1.mga7.x86_64
- lib64evview3_3-3.32.1-1.mga7.x86_64

-- rebooted for glibc (not sure why that was added)

opened a set of pictures in a cbt file
pdf document

The application worked as designed.

Ran from terminal - no messages there.

CC: (none) => brtians1
Whiteboard: (none) => MGA7-64-OK

Comment 6 Brian Rockwell 2019-11-26 17:47:35 CET
(In reply to Brian Rockwell from comment #5)
> The following 5 packages are going to be installed:
> 
> - evince-3.32.1-1.mga7.x86_64
> - glibc-2.29-19.mga7.x86_64
> - lib64evdocument3_4-3.32.1-1.mga7.x86_64
> - lib64evince-gir3.0-3.32.1-1.mga7.x86_64
> - lib64evview3_3-3.32.1-1.mga7.x86_64
> 
> -- rebooted for glibc (not sure why that was added)
> 
> opened a set of pictures in a cbt file
> pdf document
> 
> The application worked as designed.
> 
> Ran from terminal - no messages there.

This was run on 

$ uname -a
Linux linux.local 5.3.11-desktop-1.mga7 #1 SMP Tue Nov 12 21:10:01 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

Gnome desktop, VirtualBox VM.
Comment 7 David Walser 2019-11-26 19:34:21 CET
Nicolas, another TIFF issue in Evince is CVE-2019-1010006:
https://lists.opensuse.org/opensuse-updates/2019-08/msg00095.html

Do we have the fix for that?
Comment 8 Nicolas Salguero 2019-11-26 20:49:10 CET
(In reply to David Walser from comment #7)
> Nicolas, another TIFF issue in Evince is CVE-2019-1010006:
> https://lists.opensuse.org/opensuse-updates/2019-08/msg00095.html
> 
> Do we have the fix for that?

According to what I found, that CVE only affects evince 3.26.x.
Comment 9 Thomas Andrews 2019-11-30 23:41:39 CET
Well Gentlemen, do we let this go or not? My search agrees with Nicolas, but with my inexperience in such matters any results I have are unreliable, at best.

So it's up to you. I'm ready to validate, unless one of you objects.

CC: (none) => andrewsfarm

Comment 10 David Walser 2019-11-30 23:49:26 CET
Go for it.
Comment 11 Thomas Andrews 2019-12-01 00:59:43 CET
Thank you, David. Validating. Advisory in Comment 4.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Thomas Backlund 2019-12-06 12:15:03 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 12 Mageia Robot 2019-12-06 15:17:09 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0355.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.