Bug 844105 (CVE-2012-3438)
Summary: | CVE-2012-3438 GraphicsMagick: png_IM_malloc() size argument | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | andreas, rdieter, tgl |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-10-15 14:29:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 844106, 844107 | ||
Bug Blocks: | 844110 |
Description
Kurt Seifried
2012-07-28 23:01:27 UTC
Created GraphicsMagick tracking bugs for this issue Affects: fedora-all [bug 844106] Created GraphicsMagick tracking bugs for this issue Affects: epel-all [bug 844107] I'm told upstream has already committed a fix for this, so you should be able to pull a patch out of their SCM. Upstream patch: http://graphicsmagick.hg.sourceforge.net/hgweb/graphicsmagick/graphicsmagick/rev/d6e469d02cd2 Just to note, that CVE-2012-3437 is for this flaw in ImageMagick, while CVE-2012-3438 is for this flaw in GraphicsMagick. The initial description does not make it clear that separate CVEs were assigned for each. |