Bug 603081
| Summary: | libtiff: OOB read in putcontig8bitYCbCr11tile | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Tomas Hoger <thoger> | ||||||
| Component: | libtiff | Assignee: | Tom Lane <tgl> | ||||||
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Martin Cermak <mcermak> | ||||||
| Severity: | medium | Docs Contact: | |||||||
| Priority: | medium | ||||||||
| Version: | 6.0 | CC: | azelinka, herrold, hhorak, kees, mcermak, vdanen | ||||||
| Target Milestone: | rc | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | All | ||||||||
| OS: | Linux | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | libtiff-3.9.4-1.el6 | Doc Type: | Bug Fix | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2010-11-10 21:04:39 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Bug Depends On: | |||||||||
| Bug Blocks: | 611900 | ||||||||
| Attachments: |
|
||||||||
|
Description
Tomas Hoger
2010-06-11 13:45:32 UTC
Created attachment 423278 [details] Reproducer Test file from: https://bugs.launchpad.net/bugs/591605 Adding as private for now, while Launchpad bug is private. This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux major release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Major release. This request is not yet committed for inclusion. Created attachment 423329 [details]
patch
Specifically, what we need is this patch, which duplicates into PickContigCase() a safety check that already existed in PickSeparateCase().
Comment #0 fails to spell out a test case ... try this: tiff2rgba lp591605-sample.tif /dev/null Opening bug, original launchpad report is public now. Filed upstream at http://bugzilla.maptools.org/show_bug.cgi?id=2216 This issue was assigned CVE-2010-2483 => VERIFIED Red Hat Enterprise Linux 6.0 is now available and should resolve the problem described in this bug report. This report is therefore being closed with a resolution of CURRENTRELEASE. You may reopen this bug report if the solution does not work for you. |