ALT-BU-2020-3618-2
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-7998
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.
- https://github.com/jcupitt/libvips/commit/20d840e6da15c1574b3ed998bc92f91d1e36c2a5
- https://github.com/jcupitt/libvips/commit/20d840e6da15c1574b3ed998bc92f91d1e36c2a5
- https://github.com/jcupitt/libvips/issues/893
- https://github.com/jcupitt/libvips/issues/893
- [debian-lts-announce] 20180311 [SECURITY] [DLA 1306-1] vips security update
- [debian-lts-announce] 20180311 [SECURITY] [DLA 1306-1] vips security update
Modified: 2024-11-21
CVE-2019-17534
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16796
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16796
- https://github.com/libvips/libvips/commit/ce684dd008532ea0bf9d4a1d89bacb35f4a83f4d
- https://github.com/libvips/libvips/commit/ce684dd008532ea0bf9d4a1d89bacb35f4a83f4d
- https://github.com/libvips/libvips/compare/v8.8.1...v8.8.2
- https://github.com/libvips/libvips/compare/v8.8.1...v8.8.2
Modified: 2024-11-21
CVE-2019-6976
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.
- https://blog.silentsignal.eu/2019/04/18/drop-by-drop-bleeding-through-libvips/
- https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a
- https://github.com/libvips/libvips/releases/tag/v8.7.4
- https://blog.silentsignal.eu/2019/04/18/drop-by-drop-bleeding-through-libvips/
- https://github.com/libvips/libvips/releases/tag/v8.7.4
- https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a
Modified: 2024-11-21
CVE-2020-20739
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
- https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a
- https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a
- https://github.com/libvips/libvips/issues/1419
- https://github.com/libvips/libvips/issues/1419
- [debian-lts-announce] 20201130 [SECURITY] [DLA 2473-1] vips security update
- [debian-lts-announce] 20201130 [SECURITY] [DLA 2473-1] vips security update
- FEDORA-2020-d82261f7b1
- FEDORA-2020-d82261f7b1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-17514
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable