Bug 491853 (CVE-2009-0792) - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
Summary: CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2009-0792
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 491854 491855 491856 491857 491858 495915 495916 495917
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-03-24 13:21 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:29 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2010-07-13 14:26:22 UTC
Embargoed:


Attachments (Terms of Use)
Updated ghostscript-CVE-2009-0792.patch (adds checks for all 'floor' occurences) (6.53 KB, patch)
2009-04-08 11:55 UTC, Jan Lieskovsky
no flags Details | Diff
Updated Argyllcms CVE-2009-0792 (all changes in one file) patch (6.53 KB, patch)
2009-04-08 13:24 UTC, Jan Lieskovsky
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:0420 0 normal SHIPPED_LIVE Moderate: ghostscript security update 2009-04-14 17:47:31 UTC
Red Hat Product Errata RHSA-2009:0421 0 normal SHIPPED_LIVE Moderate: ghostscript security update 2009-04-14 17:54:02 UTC

Description Jan Lieskovsky 2009-03-24 13:21:42 UTC
Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found,
the original patch, addressing this issue was incomplete.

Comment 4 Jan Lieskovsky 2009-04-08 11:55:00 UTC
Created attachment 338699 [details]
Updated ghostscript-CVE-2009-0792.patch (adds checks for all 'floor' occurences)

Comment 5 Jan Lieskovsky 2009-04-08 13:24:37 UTC
Created attachment 338705 [details]
Updated Argyllcms CVE-2009-0792 (all changes in one file) patch

Comment 6 Gwyn Ciesla 2009-04-08 15:00:19 UTC
argyllcms has now been built with this patch for rawhide, F-10 and F-9, and Bodhi updates for F-10 and F-9 have been created.

Comment 11 Fedora Update System 2009-04-09 16:07:02 UTC
argyllcms-1.0.3-4.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2009-04-09 16:07:52 UTC
argyllcms-1.0.3-4.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 errata-xmlrpc 2009-04-14 17:54:05 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:0421 https://rhn.redhat.com/errata/RHSA-2009-0421.html

Comment 16 Fedora Update System 2009-04-15 17:11:19 UTC
ghostscript-8.63-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ghostscript-8.63-3.fc9

Comment 17 Fedora Update System 2009-04-15 21:49:38 UTC
ghostscript-8.63-6.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 18 Fedora Update System 2009-04-15 21:50:10 UTC
ghostscript-8.63-3.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 19 Gwyn Ciesla 2009-04-16 19:23:06 UTC
Turns out I added the patch to argyllcms but failed to apply it.  Built in rawhide, others are on their way.  My apologies for the mixup.

Rel-eng ticket filed for Freeze Exception.
https://fedorahosted.org/rel-eng/ticket/1497

Comment 20 Fedora Update System 2009-04-16 19:26:57 UTC
argyllcms-1.0.3-5.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-5.fc9

Comment 21 Fedora Update System 2009-04-16 19:27:02 UTC
argyllcms-1.0.3-5.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-5.fc10

Comment 22 Fedora Update System 2009-04-17 18:02:47 UTC
argyllcms-1.0.3-5.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 23 Fedora Update System 2009-04-17 18:06:11 UTC
argyllcms-1.0.3-5.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.