Bug 807994 (CVE-2012-0260) - CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
Summary: CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images wi...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-0260
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 796844 796845 804787 804788 808159
Blocks: 789444
TreeView+ depends on / blocked
 
Reported: 2012-03-29 10:05 UTC by Stefan Cornelius
Modified: 2023-05-12 12:16 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-19 21:52:36 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:0544 0 normal SHIPPED_LIVE Moderate: ImageMagick security update 2012-05-07 22:22:16 UTC
Red Hat Product Errata RHSA-2012:0545 0 normal SHIPPED_LIVE Moderate: ImageMagick security and bug fix update 2012-05-07 22:21:08 UTC

Description Stefan Cornelius 2012-03-29 10:05:53 UTC
A denial of service flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, decoded certain JPEG images. A remote attacker could provide a JPEG image with specially-crafted values / sequences of RST0 up to RST7 restart markers (used to indicate the input stream to be corrupted), which once processed by some ImageMagick tool would lead that tool to consume excessive amount of CPU time (denial of service).

Upstream patch:

[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629

Comment 1 Jan Lieskovsky 2012-03-29 17:04:36 UTC
Acknowledgements:

Red Hat would like to thank CERT-FI for reporting this issue. CERT-FI acknowledges Aleksis Kauppinen, Joonas Kuorilehto, Tuomas Parttimaa and Lasse Ylivainio of Codenomicon's CROSS project as the original reporters.

Comment 2 Jan Lieskovsky 2012-03-29 17:30:19 UTC
This issue affects the versions of the ImageMagick package, as shipped with Fedora release of 15 and 16.

Comment 3 Jan Lieskovsky 2012-03-29 17:41:57 UTC
Public now via:
[2] http://www.cert.fi/en/reports/2012/vulnerability635606.html

Comment 4 Jan Lieskovsky 2012-03-29 17:43:41 UTC
Created ImageMagick tracking bugs for this issue

Affects: fedora-all [bug 808159]

Comment 5 Stefan Cornelius 2012-03-30 11:58:38 UTC
This issue affects the versions of the ImageMagick package, as shipped with Red Hat Enterprise Linux 5 and 6.

Comment 6 Pavel Alexeev 2012-04-11 13:29:03 UTC
Rawhide build which should fix it http://koji.fedoraproject.org/koji/taskinfo?taskID=3977291.

Comment 7 errata-xmlrpc 2012-05-07 18:48:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2012:0545 https://rhn.redhat.com/errata/RHSA-2012-0545.html

Comment 8 errata-xmlrpc 2012-05-07 18:51:32 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:0544 https://rhn.redhat.com/errata/RHSA-2012-0544.html


Note You need to log in before you can comment on or make changes to this bug.