Bug 430241 - SDL_image / gd: GIF handling buffer overflow
Summary: SDL_image / gd: GIF handling buffer overflow
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: SDL_image
Version: 7
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Brian Pepple
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: CVE-2007-6697
TreeView+ depends on / blocked
 
Reported: 2008-01-25 15:07 UTC by Brian Pepple
Modified: 2008-02-02 08:59 UTC (History)
1 user (show)

Fixed In Version: 1.2.5-7.fc7
Clone Of:
Environment:
Last Closed: 2008-02-02 01:20:25 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Brian Pepple 2008-01-25 15:07:29 UTC
Description of problem: How reproducible: Input validation flaw was discovered
in the SDL_image image handling library. Value read from the Gif file is not
properly validated against the buffer size and can cause a buffer overflow.

Comment 1 Fedora Update System 2008-01-27 07:28:49 UTC
SDL_image-1.2.5-6.fc7 has been pushed to the Fedora 7 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update SDL_image'.  You can provide feedback for this update here: http://admin.fedoraproject.org/F7/FEDORA-2008-1116

Comment 2 Fedora Update System 2008-01-29 20:26:52 UTC
SDL_image-1.2.5-7.fc7 has been submitted as an update for Fedora 7

Comment 3 Fedora Update System 2008-02-02 01:20:18 UTC
SDL_image-1.2.5-7.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2008-02-02 08:59:19 UTC
SDL_image-1.2.5-7.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.