Bug 1588803 (CVE-2018-11813)

Summary: CVE-2018-11813 libjpeg: "cjpeg" utility large loop because read_pixel in rdtarga.c mishandles EOF
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: gsuckevi, negativo17, nforro, phracek, vonsch
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-06 19:19:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1588804, 1588806, 1588807, 1588808, 1591203    
Bug Blocks: 1588809, 1849034    

Description Pedro Sampaio 2018-06-07 21:18:50 UTC
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

References:

https://github.com/ChijinZ/security_advisories/blob/master/libjpeg-v9c/mail.pdf
https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9c

Comment 1 Pedro Sampaio 2018-06-07 21:19:13 UTC
Created libjpeg-turbo tracking bugs for this issue:

Affects: fedora-all [bug 1588804]

Comment 2 Pedro Sampaio 2018-06-07 21:20:38 UTC
Created mingw-libjpeg-turbo tracking bugs for this issue:

Affects: epel-7 [bug 1588806]
Affects: fedora-all [bug 1588808]

Comment 4 Stefan Cornelius 2018-06-14 09:07:54 UTC
Patch (libjpeg-turbo):
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/909a8cfc7bca9b2e6707425bdb74da997e8fa499

The following section in the upstream changelog entry is noteworthy:
"[...] Because this issue only affected cjpeg and not the underlying library, and because it did not involve any out-of-bounds reads or other exploitable behaviors, it was not believed to represent a security threat."

Comment 6 Stefan Cornelius 2018-06-14 09:31:38 UTC
Statement:

This issue affects the versions of libjpeg as shipped with Red Hat Enterprise Linux 4 and 5. This issue affects the versions of libjpeg-turbe as shipped with Red Hat Enterprise Linux 6 and 7. However, the problem is limited to the "cjpeg" utility and does not affect the library itself.

Comment 8 errata-xmlrpc 2019-08-06 12:08:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2052 https://access.redhat.com/errata/RHSA-2019:2052

Comment 9 Product Security DevOps Team 2019-08-06 19:19:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-11813

Comment 10 Doran Moppert 2020-08-07 00:32:06 UTC
*** Bug 1849031 has been marked as a duplicate of this bug. ***