This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 494823 - (CVE-2005-3350) CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF
CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
http://web.nvd.nist.gov/view/vuln/det...
impact=important,source=vendorsec,pub...
: Security
: 491727 (view as bug list)
Depends On: 171413 491727 493567 493568
Blocks:
  Show dependency treegraph
 
Reported: 2009-04-08 05:32 EDT by Tomas Hoger
Modified: 2009-11-19 10:07 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-11-19 10:07:22 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
Chris Evans' PoC - bad2.gif (16.41 KB, image/gif)
2009-04-08 05:35 EDT, Tomas Hoger
no flags Details
Chris Evans' PoC - bad3.gif (16.41 KB, image/gif)
2009-04-08 05:35 EDT, Tomas Hoger
no flags Details

  None (edit)
Description Tomas Hoger 2009-04-08 05:32:16 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-3350 to the following vulnerability:

libungif library before 4.1.0 allows attackers to corrupt memory and possibly
execute arbitrary code via a crafted GIF file that leads to an out-of-bounds
write.

References:
http://scary.beasts.org/security/CESA-2005-007.txt
http://sourceforge.net/project/shownotes.php?release_id=364493
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171413
Comment 1 Tomas Hoger 2009-04-08 05:35:21 EDT
Created attachment 338675 [details]
Chris Evans' PoC - bad2.gif

Source: http://scary.beasts.org/security/CESA-2005-007.txt

Crash can be reproduced using e.g. gif2ps from giflib-utils
Comment 2 Tomas Hoger 2009-04-08 05:35:53 EDT
Created attachment 338676 [details]
Chris Evans' PoC - bad3.gif

Source: http://scary.beasts.org/security/CESA-2005-007.txt
Comment 4 errata-xmlrpc 2009-04-22 13:37:34 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:0444 https://rhn.redhat.com/errata/RHSA-2009-0444.html
Comment 5 Fedora Update System 2009-05-15 21:53:37 EDT
giflib-4.1.3-10.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/giflib-4.1.3-10.fc9
Comment 6 Fedora Update System 2009-05-18 22:09:13 EDT
giflib-4.1.3-10.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Tomas Hoger 2009-05-25 14:29:10 EDT
The fix for this issue has raised few questions related to the late release of the updates for this flaw.  Here are few more details about the cause of this and the time line.

This problem (along with the crash-only issue CVE-2005-2974) was reported in October 2005 and was originally tracked via bug #171413.  Updates addressing this flaw were released for libungif packages shipped in the current versions of Red Hat Enterprise Linux (2.1 to 4):

https://rhn.redhat.com/errata/CVE-2005-3350.html
  https://rhn.redhat.com/errata/RHSA-2005-828.html

and Fedora Core (3 and 4):

http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00004.html
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00005.html

SRPMs for updated packages can be found on Red Hat FTP (RHEL updates):

https://www.redhat.com/archives/enterprise-watch-list/2005-November/msg00004.html
  (has FTP links for individual SRPMs)

or Fedora Project's archive FTP (FC updates):

http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/3/SRPMS/libungif-4.1.3-1.fc3.2.src.rpm
http://archive.fedoraproject.org/pub/archive/fedora/linux/core/updates/4/SRPMS/libungif-4.1.3-3.fc4.2.src.rpm

Later on, in between Fedora Core 4 and 5, libungif package was replaced with giflib.  libungif and giflib differ in the support for patented LZW algorithm, libungif can only create uncompressed gif images, and is now no longer maintained upstream after patent expiration:

https://sourceforge.net/forum/forum.php?forum_id=753553

According to giflib's RPM changelog, the work on libungif -> giflib transition started in September 2005 and the patch for the flaw did not get included in giflib packages.  Fedora Core 5 was released with affected giflib 4.1.3, which has not been updated to newer upstream version in Fedora Core and Fedora until recently.  It was also included in Red Hat Enterprise Linux 5 (which was based on Fedora Core 6).  Missing fix for the giflib was only spotted recently.

Updated Fedora giflib packages can be found at:

https://admin.fedoraproject.org/updates/giflib
  https://admin.fedoraproject.org/updates/F9/FEDORA-2009-5118
  https://admin.fedoraproject.org/updates/F10/FEDORA-2009-4848

Fedora 9 packages got backported patch included and are already available in the stable repository.  For Fedora 10, giflib was rebased to the current upstream version 4.1.6 and is available in the testing repository at the moment.
Comment 8 Fedora Update System 2009-06-18 07:39:26 EDT
giflib-4.1.6-2.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.