Bug 807994 (CVE-2012-0260)

Summary: CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
Product: [Other] Security Response Reporter: Stefan Cornelius <scorneli>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: jlieskov, kem, nmurray, pahan, rrosario, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-19 21:52:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 796844, 796845, 804787, 804788, 808159    
Bug Blocks: 789444    

Description Stefan Cornelius 2012-03-29 10:05:53 UTC
A denial of service flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, decoded certain JPEG images. A remote attacker could provide a JPEG image with specially-crafted values / sequences of RST0 up to RST7 restart markers (used to indicate the input stream to be corrupted), which once processed by some ImageMagick tool would lead that tool to consume excessive amount of CPU time (denial of service).

Upstream patch:

[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629

Comment 1 Jan Lieskovsky 2012-03-29 17:04:36 UTC
Acknowledgements:

Red Hat would like to thank CERT-FI for reporting this issue. CERT-FI acknowledges Aleksis Kauppinen, Joonas Kuorilehto, Tuomas Parttimaa and Lasse Ylivainio of Codenomicon's CROSS project as the original reporters.

Comment 2 Jan Lieskovsky 2012-03-29 17:30:19 UTC
This issue affects the versions of the ImageMagick package, as shipped with Fedora release of 15 and 16.

Comment 3 Jan Lieskovsky 2012-03-29 17:41:57 UTC
Public now via:
[2] http://www.cert.fi/en/reports/2012/vulnerability635606.html

Comment 4 Jan Lieskovsky 2012-03-29 17:43:41 UTC
Created ImageMagick tracking bugs for this issue

Affects: fedora-all [bug 808159]

Comment 5 Stefan Cornelius 2012-03-30 11:58:38 UTC
This issue affects the versions of the ImageMagick package, as shipped with Red Hat Enterprise Linux 5 and 6.

Comment 6 Pavel Alexeev 2012-04-11 13:29:03 UTC
Rawhide build which should fix it http://koji.fedoraproject.org/koji/taskinfo?taskID=3977291.

Comment 7 errata-xmlrpc 2012-05-07 18:48:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2012:0545 https://rhn.redhat.com/errata/RHSA-2012-0545.html

Comment 8 errata-xmlrpc 2012-05-07 18:51:32 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:0544 https://rhn.redhat.com/errata/RHSA-2012-0544.html