Bug 1354500 (CVE-2016-5010)
Summary: | CVE-2016-5010 ImageMagick: Out-of-bounds read when processing crafted tiff file | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | abhgupta, dmcphers, jhorak, jialiu, jokerman, kseifried, lmeyer, mmccomas, security-response-team, slawomir, tiwillia |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | ImageMagick 6.9.5-3 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-04-03 23:56:28 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1361578 | ||
Bug Blocks: | 1354508, 1378785 |
Description
Adam Mariš
2016-07-11 12:36:34 UTC
Acknowledgments: Name: Shi Pu (China Electronic Technology Cyber Security) Upstream patch: http://git.imagemagick.org/repos/ImageMagick/commit/c20de102cc57f3739a8870f79e728e3b0bea18c0 Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1361578] In reply to comment 4: > Upstream patch: > > http://git.imagemagick.org/repos/ImageMagick/commit/ > c20de102cc57f3739a8870f79e728e3b0bea18c0 Having trouble accessing this, but https://github.com/ImageMagick/ImageMagick/commit/803bc34ebe023f209f745baf8a112610ff77cc8c works and appears to fix this issue. Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. |