Bug 1382202 (CVE-2016-9675)

Summary: CVE-2016-9675 openjpeg: incorrect fix for CVE-2013-6045
Product: [Other] Security Response Reporter: Doran Moppert <dmoppert>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dmoppert, erik-fedora, extras-orphan, jaromir.capik, kabbott, manisandro, nforro, oliver, phracek, rdieter, slawomir
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openjpeg 1.5.2 Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in the patch for CVE-2013-6045 for OpenJPEG. A specially crafted JPEG2000 image, when read by an application using OpenJPEG, could cause heap-based buffer overflows leading to a crash or possible code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:59:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1382204, 1382205, 1419772, 1419773, 1419774, 1419775    
Bug Blocks: 1374338    

Description Doran Moppert 2016-10-06 00:48:49 UTC
A flaw was found in the patch for CVE-2013-6045 for openjpeg-1.  A crafted
jpeg2000 image could cause heap-based buffer overflows, leading to a crash or
possible code execution when reading or converting the crafted file.

External reference:

http://seclists.org/oss-sec/2016/q3/624

See also:

https://bugzilla.redhat.com/show_bug.cgi?id=1036495#c20
https://bugs.debian.org/734238

Adjusted patch attached, but see also:

http://pkgs.fedoraproject.org/cgit/rpms/openjpeg.git/commit/?id=ecc78395d2c04b4bc4e37435c2c9c5a603f8910a

Comment 1 Doran Moppert 2016-10-06 00:49:42 UTC
Created openjpeg tracking bugs for this issue:

Affects: epel-5 [bug 1382205]

Comment 2 Doran Moppert 2016-10-06 00:49:49 UTC
Created mingw-openjpeg tracking bugs for this issue:

Affects: fedora-all [bug 1382204]

Comment 3 Doran Moppert 2016-11-01 03:27:48 UTC
Acknowledgments:

Name: Doran Moppert (Red Hat Product Security)

Comment 17 errata-xmlrpc 2017-03-20 01:22:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:0559 https://rhn.redhat.com/errata/RHSA-2017-0559.html

Comment 18 errata-xmlrpc 2017-03-23 03:46:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0838 https://rhn.redhat.com/errata/RHSA-2017-0838.html