~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-14175

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-09-07
2
 
Candidate: CVE-2017-14175
3
 
PublicDate: 2017-09-07
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14175
6
 
 https://usn.ubuntu.com/usn/usn-3681-1
7
 
Description:
8
 
 In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to
9
 
 lack of an EOF (End of File) check might cause huge CPU consumption. When a
10
 
 crafted XBM file, which claims large rows and columns fields in the header
11
 
 but does not contain sufficient backing data, is provided, the loop over
12
 
 the rows would consume huge CPU resources, since there is no EOF check
13
 
 inside the loop.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
 mdeslaur> 0314-CVE-2017-14175-Fix-DoS-missing-EOF-check-in-ReadXBMImage-1-of-2.patch and
17
 
 mdeslaur> 0315-CVE-2017-14175-Fix-DoS-missing-EOF-check-in-ReadXBMImage-2-of-2.patch in wheezy
18
 
Bugs:
19
 
 https://github.com/ImageMagick/ImageMagick/issues/712
20
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=875502
21
 
Priority: low
22
 
Discovered-by: Hao Sun
23
 
Assigned-to:
24
 
 
25
 
Patches_imagemagick:
26
 
 upstream: https://github.com/ImageMagick/ImageMagick/commit/b8c63b156bf26b52e710b1a0643c846a6cd01e56
27
 
 upstream: https://github.com/ImageMagick/ImageMagick/commit/169a20e13ee634aba7ebab94775497d6a89f5ec1
28
 
upstream_imagemagick: released (8:6.9.9.34+dfsg-3)
29
 
precise/esm_imagemagick: DNE
30
 
trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.11)
31
 
vivid/ubuntu-core_imagemagick: DNE
32
 
xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.11)
33
 
zesty_imagemagick: ignored (reached end-of-life)
34
 
artful_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu2.2)
35
 
bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.2)
36
 
devel_imagemagick: needed