Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 16 May 2016 09:53:24 +0200
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Cc: CVE Assignments MITRE <cve-assign@...re.org>
Subject: Re: CVE Request: gdk-pixbuf: Additional fixes to
 protect against overlows in pixops_* functions (similar to CVE-2015-7674)

Hi,

On Thu, May 12, 2016 at 11:23:02AM +0200, Salvatore Bonaccorso wrote:
> Hi
> 
> CVE-2015-7674, an interger overflow flaw in the pixops_scale_nearest
> function, was fixed by
> 
> https://git.gnome.org/browse/gdk-pixbuf/commit/?id=e9a5704edaa9aee9498f1fbf6e1b70fcce2e55aa
> 
> There is another commit in the gdk-pixbuf repository to fix overflows
> in the pixops_composite_nearest, pixops_composite_color_nearest and
> pixops_process functions:
> 
> https://git.gnome.org/browse/gdk-pixbuf/commit/?id=dbfe8f70471864818bf458a39c8a99640895bd22
> 
> Can you aassing an additional CVE for this since the scope for
> CVE-2015-7674 was for the pixops_scale_nearest function?

I realise I did not made that clear: The two commits were not fixed in
the same release, the initial one resulting in CVE-2015-7674 is
contained in 2.32.1, wereas the second commit came later in 2.33.1.

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.