Bug 430239 - SDL_image / gd: GIF handling buffer overflow
Summary: SDL_image / gd: GIF handling buffer overflow
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: SDL_image
Version: 8
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Brian Pepple
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: CVE-2007-6697
TreeView+ depends on / blocked
 
Reported: 2008-01-25 14:56 UTC by Brian Pepple
Modified: 2008-02-02 01:18 UTC (History)
1 user (show)

Fixed In Version: 1.2.6-5.fc8
Clone Of:
Environment:
Last Closed: 2008-02-02 01:18:47 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Brian Pepple 2008-01-25 14:56:50 UTC
Description of problem:

How reproducible: Input validation flaw was discovered in the SDL_image
image handling library. Value read from the Gif file is not properly validated
against the buffer size and can cause a buffer overflow.

Comment 1 Tomas Hoger 2008-01-25 15:05:11 UTC
Brian, feel free to mention #430100 in the RPM changelog, as that bug is
expected to contain more details about the issue.

Comment 2 Fedora Update System 2008-01-27 07:28:55 UTC
SDL_image-1.2.6-4.fc8 has been pushed to the Fedora 8 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update SDL_image'.  You can provide feedback for this update here: http://admin.fedoraproject.org/F8/FEDORA-2008-1117

Comment 3 Fedora Update System 2008-02-02 01:18:43 UTC
SDL_image-1.2.6-5.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.