Bug 1301614 (CVE-2014-9762, CVE-2014-9763, CVE-2014-9764)

Summary: CVE-2014-9762 imlib2: security issues fixed in 1.4.7
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: andreas.bierfert, carnil, pahan, tsmetana
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: imlib2 1.4.7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:47:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1301615, 1301616, 1301617    
Bug Blocks:    

Description Andrej Nemec 2016-01-25 14:18:20 UTC
Multiple security issues were addressed in the imlib2-1.4.7 version.


Original bug report:

http://seclists.org/oss-sec/2016/q1/162

CVE assignment:

http://seclists.org/oss-sec/2016/q1/182

Upstream git patches:

CVE-2014-9762, segmentation fault on images without colormap:

https://git.enlightenment.org/legacy/imlib2.git/commit/?h=v1.4.7&id=39641e74a560982fbf93f29bf96b37d27803cb56

CVE-2014-9763, divison-by-zero crash:

https://git.enlightenment.org/legacy/imlib2.git/commit/?h=v1.4.7&id=c21beaf1780cf3ca291735ae7d58a3dde63277a2

CVE-2014-9764, segmentation fault when opening specifically crafted input:

https://git.enlightenment.org/legacy/imlib2.git/commit/?h=v1.4.7&id=1f9b0b32728803a1578e658cd0955df773e34f49

Comment 1 Andrej Nemec 2016-01-25 14:18:55 UTC
Created imlib2 tracking bugs for this issue:

Affects: fedora-all [bug 1301615]
Affects: epel-6 [bug 1301616]
Affects: epel-7 [bug 1301617]

Comment 2 Tomas Smetana 2016-01-25 16:21:18 UTC
There is no ABI incompatibility between 1.4.6 and 1.4.7 so it should be OK to rebase.

Comment 3 Fedora Update System 2016-01-30 18:20:42 UTC
imlib2-1.4.7-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2016-02-10 10:51:31 UTC
imlib2-1.4.7-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Product Security DevOps Team 2019-06-08 02:47:43 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.