Bug 542700 (CVE-2009-3994)

Summary: CVE-2009-3994 DevIL: Insufficient input sanitation by processing DICOM images
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: hdegoede, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-03-29 10:06:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2009-11-30 15:39:59 UTC
Stefan Cornelius of Secunia Research found an insufficient
input sanitation in the way DevIL image library used to process
Digital Imaging and Communications in Medicine (DICOM) images.
If a remote attacker could trick a local user to process
a specially-crafted DICOM image in an application, using
the DevIL image processing library, it could lead to
stack-based buffer overflow and denial of service (application
crash).

Comment 4 Jan Lieskovsky 2009-12-04 12:26:42 UTC
Issue now public via:
    http://sourceforge.net/tracker/?func=detail&aid=2908728&group_id=4470&atid=304470

Comment 7 Tomas Hoger 2009-12-14 14:41:46 UTC
Secunia advisories:
  http://secunia.com/advisories/37507/
  http://secunia.com/secunia_research/2009-51/

Comment 9 Fedora Update System 2009-12-15 08:27:41 UTC
DevIL-1.7.8-4.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/DevIL-1.7.8-4.fc11

Comment 10 Fedora Update System 2009-12-15 08:27:49 UTC
DevIL-1.7.8-4.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/DevIL-1.7.8-4.fc12

Comment 11 Fedora Update System 2010-01-12 23:29:43 UTC
DevIL-1.7.8-4.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2010-01-12 23:52:04 UTC
DevIL-1.7.8-4.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.