Bug 494823 (CVE-2005-3350) - CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF
Summary: CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2005-3350
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard:
: 491727 (view as bug list)
Depends On: 171413 491727 493567 493568
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-04-08 09:32 UTC by Tomas Hoger
Modified: 2019-09-29 12:29 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-11-19 15:07:22 UTC


Attachments (Terms of Use)
Chris Evans' PoC - bad2.gif (16.41 KB, image/gif)
2009-04-08 09:35 UTC, Tomas Hoger
no flags Details
Chris Evans' PoC - bad3.gif (16.41 KB, image/gif)
2009-04-08 09:35 UTC, Tomas Hoger
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:0444 0 normal SHIPPED_LIVE Important: giflib security update 2009-04-22 17:37:31 UTC

Description Tomas Hoger 2009-04-08 09:32:16 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-3350 to the following vulnerability:

libungif library before 4.1.0 allows attackers to corrupt memory and possibly
execute arbitrary code via a crafted GIF file that leads to an out-of-bounds
write.

References:
http://scary.beasts.org/security/CESA-2005-007.txt
http://sourceforge.net/project/shownotes.php?release_id=364493
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171413

Comment 1 Tomas Hoger 2009-04-08 09:35:21 UTC
Created attachment 338675 [details]
Chris Evans' PoC - bad2.gif

Source: http://scary.beasts.org/security/CESA-2005-007.txt

Crash can be reproduced using e.g. gif2ps from giflib-utils

Comment 2 Tomas Hoger 2009-04-08 09:35:53 UTC
Created attachment 338676 [details]
Chris Evans' PoC - bad3.gif

Source: http://scary.beasts.org/security/CESA-2005-007.txt

Comment 4 errata-xmlrpc 2009-04-22 17:37:34 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:0444 https://rhn.redhat.com/errata/RHSA-2009-0444.html

Comment 5 Fedora Update System 2009-05-16 01:53:37 UTC
giflib-4.1.3-10.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/giflib-4.1.3-10.fc9

Comment 6 Fedora Update System 2009-05-19 02:09:13 UTC
giflib-4.1.3-10.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Tomas Hoger 2009-05-25 18:29:10 UTC
The fix for this issue has raised few questions related to the late release of the updates for this flaw.  Here are few more details about the cause of this and the time line.

This problem (along with the crash-only issue CVE-2005-2974) was reported in October 2005 and was originally tracked via bug #171413.  Updates addressing this flaw were released for libungif packages shipped in the current versions of Red Hat Enterprise Linux (2.1 to 4):

https://rhn.redhat.com/errata/CVE-2005-3350.html
  https://rhn.redhat.com/errata/RHSA-2005-828.html

and Fedora Core (3 and 4):

http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00004.html
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00005.html

SRPMs for updated packages can be found on Red Hat FTP (RHEL updates):

https://www.redhat.com/archives/enterprise-watch-list/2005-November/msg00004.html
  (has FTP links for individual SRPMs)

or Fedora Project's archive FTP (FC updates):

http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/3/SRPMS/libungif-4.1.3-1.fc3.2.src.rpm
http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/4/SRPMS/libungif-4.1.3-3.fc4.2.src.rpm

Later on, in between Fedora Core 4 and 5, libungif package was replaced with giflib.  libungif and giflib differ in the support for patented LZW algorithm, libungif can only create uncompressed gif images, and is now no longer maintained upstream after patent expiration:

https://sourceforge.net/forum/forum.php?forum_id=753553

According to giflib's RPM changelog, the work on libungif -> giflib transition started in September 2005 and the patch for the flaw did not get included in giflib packages.  Fedora Core 5 was released with affected giflib 4.1.3, which has not been updated to newer upstream version in Fedora Core and Fedora until recently.  It was also included in Red Hat Enterprise Linux 5 (which was based on Fedora Core 6).  Missing fix for the giflib was only spotted recently.

Updated Fedora giflib packages can be found at:

https://admin.fedoraproject.org/updates/giflib
  https://admin.fedoraproject.org/updates/F9/FEDORA-2009-5118
  https://admin.fedoraproject.org/updates/F10/FEDORA-2009-4848

Fedora 9 packages got backported patch included and are already available in the stable repository.  For Fedora 10, giflib was rebased to the current upstream version 4.1.6 and is available in the testing repository at the moment.

Comment 8 Fedora Update System 2009-06-18 11:39:26 UTC
giflib-4.1.6-2.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.