Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 22 May 2017 17:58:31 -0500 (CDT)
From: Bob Friesenhahn <bfriesen@...ple.dallas.tx.us>
To: Thomas Deutschmann <whissi@...too.org>
cc: oss-security@...ts.openwall.com
Subject: Re: Re: ImageMagick: CVE-2017-9098: use of uninitialized
 memory in RLE decoder

On Mon, 22 May 2017, Thomas Deutschmann wrote:

> Hi,
>
> let me take the opportunity to jump into this.
>
> Bob, do you have any PoC you can share with ImageMagick project
> regarding CVE-2017-6335?
>
> Your fix was
> https://sourceforge.net/p/graphicsmagick/code/ci/6156b4c2992d855ece6079653b3b93c3229fc4b8/
>
> I asked ImageMagick project about that issue but they don't know without
> a PoC, see https://github.com/ImageMagick/ImageMagick/issues/391

I have attached the problematic TIFF file.  I don't know if binary 
attachments are accepted by this list.  I can provide the full 
original report which included a PDF file if you need it.

The fix was made in code which is specific to GraphicsMagick and the 
problem may be specific to GraphicsMagick.

Bob
-- 
Bob Friesenhahn
bfriesen@...ple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.