Bug 1769540 (CVE-2019-17534)

Summary: CVE-2019-17534 vips: use-after-free in vips_foreign_load_gif_scan_image in foreign/gifload.c
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adam, bgilbert, redhat
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-08 04:32:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1769541, 1769542    
Bug Blocks:    

Description Guilherme de Almeida Suckevicz 2019-11-06 20:11:40 UTC
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.

References:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16796
https://github.com/libvips/libvips/commit/ce684dd008532ea0bf9d4a1d89bacb35f4a83f4d

Comment 1 Guilherme de Almeida Suckevicz 2019-11-06 20:11:55 UTC
Created vips tracking bugs for this issue:

Affects: fedora-29 [bug 1769541]
Affects: fedora-30 [bug 1769542]

Comment 2 Benjamin Gilbert 2019-12-06 06:18:37 UTC
F29 is EOL, F30 is unaffected, and F31/rawhide are patched.

Comment 3 Kleis Auke Wolthuizen 2020-04-25 19:35:23 UTC
For further readers; the data in NVD is incorrect. This vulnerability was only present on the libvips master branch for about 24 hours and was never included in a released version.

Please see:
https://github.com/libvips/libvips/commit/ce684dd008532ea0bf9d4a1d89bacb35f4a83f4d#commitcomment-36619649
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16796#c4