Bug 30045 - gdk-pixbuf2.0 new security issue CVE-2021-44648
Summary: gdk-pixbuf2.0 new security issue CVE-2021-44648
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-02-13 18:57 CET by David Walser
Modified: 2022-11-02 00:00 CET (History)
4 users (show)

See Also:
Source RPM: gdk-pixbuf2.0-2.42.2-1.1.mga8.src.rpm
CVE: CVE-2021-44648
Status comment:


Attachments

Description David Walser 2022-02-13 18:57:19 CET
Fedora has issued an advisory on February 12:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PEKBMOO52RXONWKB6ZKKHTVPLF6WC3KF/

Mageia 8 is also affected.
David Walser 2022-02-13 18:57:35 CET

Status comment: (none) => Patch available from Fedora
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-02-13 21:32:19 CET
Assigning to you, Olav, as the principle packager who has dealt with this.

Assignee: bugsquad => olav

Comment 2 David Walser 2022-09-07 19:19:11 CEST
openSUSE has issued an advisory for this today (September 7):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LAG7HNTW3KWGP2EF5FBPHDA3R5UPDYZY/
Comment 3 David Walser 2022-09-12 17:31:39 CEST
Debian has issued an advisory for this on September 11:
https://www.debian.org/security/2022/dsa-5228
Comment 4 David Walser 2022-09-14 22:53:50 CEST
Ubuntu has issued an advisory for this on September 13:
https://ubuntu.com/security/notices/USN-5607-1
Comment 5 Nicolas Salguero 2022-10-19 16:55:12 CEST
Hi,

Version 2.42.9 (already in Cauldron) solves that issue.

Best regards,

Nico.

Source RPM: gdk-pixbuf2.0-2.42.6-1.mga9.src.rpm => gdk-pixbuf2.0-2.42.2-1.1.mga8.src.rpm
Whiteboard: MGA8TOO => (none)
CVE: (none) => CVE-2021-44648
CC: (none) => nicolas.salguero
Status comment: Patch available from Fedora => (none)
Version: Cauldron => 8

David Walser 2022-10-19 17:45:48 CEST

Status comment: (none) => Patch available from Fedora

Comment 6 Nicolas Salguero 2022-10-20 09:39:06 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12. (CVE-2021-44648)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44648
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PEKBMOO52RXONWKB6ZKKHTVPLF6WC3KF/
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LAG7HNTW3KWGP2EF5FBPHDA3R5UPDYZY/
https://www.debian.org/security/2022/dsa-5228
https://ubuntu.com/security/notices/USN-5607-1
========================

Updated packages in core/updates_testing:
========================
gdk-pixbuf2.0-2.42.2-1.2.mga8
lib(64)gdk_pixbuf2.0_0-2.42.2-1.2.mga8
lib(64)gdk_pixbuf2.0-devel-2.42.2-1.2.mga8
lib(64)gdk_pixbuf-gir2.0-2.42.2-1.2.mga8

from SRPM:
gdk-pixbuf2.0-2.42.2-1.2.mga8.src.rpm

Assignee: olav => qa-bugs
Status comment: Patch available from Fedora => (none)
Status: NEW => ASSIGNED

Comment 7 Thomas Andrews 2022-10-29 03:30:32 CEST
MGA8-64 Plasma system. No installation issues.

I used the test procedure from https://bugs.mageia.org/show_bug.cgi?id=21658#c7 modified because the vulnerability involved decoding GIF images.

I downloaded a version of a daily comic strip, in color.

$ convert 2340248.gif mallard.jpg converted the image into JPG.
$ convert 2340248.gif -colorspace Gray mallardgray.jpg converted to JPG, in grayscale.

Both resulting images displayed perfectly in Gwenview.

Giving this an OK, and validating. Advisory in Comment 6.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK

Dave Hodgins 2022-11-01 22:43:09 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 8 Mageia Robot 2022-11-02 00:00:18 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0402.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.