MGASA-2018-0438

Source
https://advisories.mageia.org/MGASA-2018-0438.html
Import Source
https://advisories.mageia.org/MGASA-2018-0438.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0438
Related
Published
2018-11-03T19:20:21Z
Modified
2018-11-03T18:55:24Z
Summary
Updated cimg and gmic packages fix security vulnerabilities
Details

Updated cimg and gmic packages fix security vulnerabilities:

An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in load_bmp in CImg.h (CVE-2018-7587).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image (CVE-2018-7588).

An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image (CVE-2018-7589).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. This is in a "16 colors" case, aka case 4 (CVE-2018-7637).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. This is in a "256 colors" case, aka case 8 (CVE-2018-7638).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. This is in a "16 bits colors" case, aka case 16 (CVE-2018-7639).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. This is in a Monochrome case, aka case 1 (CVE-2018-7640).

An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. This is in a "32 bits colors" case, aka case 32 (CVE-2018-7641).

References
Credits

Affected packages

Mageia:6 / cimg

Package

Name
cimg
Purl
pkg:rpm/mageia/cimg?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / gmic

Package

Name
gmic
Purl
pkg:rpm/mageia/gmic?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0-1.2.mga6

Ecosystem specific

{
    "section": "core"
}