Common Vulnerabilities and Exposures assigned an identifier CVE-2005-3350 to the following vulnerability: libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write. References: http://scary.beasts.org/security/CESA-2005-007.txt http://sourceforge.net/project/shownotes.php?release_id=364493 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171413
Created attachment 338675 [details] Chris Evans' PoC - bad2.gif Source: http://scary.beasts.org/security/CESA-2005-007.txt Crash can be reproduced using e.g. gif2ps from giflib-utils
Created attachment 338676 [details] Chris Evans' PoC - bad3.gif Source: http://scary.beasts.org/security/CESA-2005-007.txt
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:0444 https://rhn.redhat.com/errata/RHSA-2009-0444.html
giflib-4.1.3-10.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/giflib-4.1.3-10.fc9
giflib-4.1.3-10.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
The fix for this issue has raised few questions related to the late release of the updates for this flaw. Here are few more details about the cause of this and the time line. This problem (along with the crash-only issue CVE-2005-2974) was reported in October 2005 and was originally tracked via bug #171413. Updates addressing this flaw were released for libungif packages shipped in the current versions of Red Hat Enterprise Linux (2.1 to 4): https://rhn.redhat.com/errata/CVE-2005-3350.html https://rhn.redhat.com/errata/RHSA-2005-828.html and Fedora Core (3 and 4): http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00004.html http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00005.html SRPMs for updated packages can be found on Red Hat FTP (RHEL updates): https://www.redhat.com/archives/enterprise-watch-list/2005-November/msg00004.html (has FTP links for individual SRPMs) or Fedora Project's archive FTP (FC updates): http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/3/SRPMS/libungif-4.1.3-1.fc3.2.src.rpm http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/4/SRPMS/libungif-4.1.3-3.fc4.2.src.rpm Later on, in between Fedora Core 4 and 5, libungif package was replaced with giflib. libungif and giflib differ in the support for patented LZW algorithm, libungif can only create uncompressed gif images, and is now no longer maintained upstream after patent expiration: https://sourceforge.net/forum/forum.php?forum_id=753553 According to giflib's RPM changelog, the work on libungif -> giflib transition started in September 2005 and the patch for the flaw did not get included in giflib packages. Fedora Core 5 was released with affected giflib 4.1.3, which has not been updated to newer upstream version in Fedora Core and Fedora until recently. It was also included in Red Hat Enterprise Linux 5 (which was based on Fedora Core 6). Missing fix for the giflib was only spotted recently. Updated Fedora giflib packages can be found at: https://admin.fedoraproject.org/updates/giflib https://admin.fedoraproject.org/updates/F9/FEDORA-2009-5118 https://admin.fedoraproject.org/updates/F10/FEDORA-2009-4848 Fedora 9 packages got backported patch included and are already available in the stable repository. For Fedora 10, giflib was rebased to the current upstream version 4.1.6 and is available in the testing repository at the moment.
giflib-4.1.6-2.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.