Bug 974202 (CVE-2011-5326) - VUL-1: CVE-2011-5326: imlib2: divide by 0 when drawing an ellipse of height 1
Summary: VUL-1: CVE-2011-5326: imlib2: divide by 0 when drawing an ellipse of height 1
Status: RESOLVED FIXED
Alias: CVE-2011-5326
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:NVD:CVE-2011-5326:5.0:(AV:N/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-04-06 07:54 UTC by Simon Lees
Modified: 2020-05-12 17:51 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Simon Lees 2016-04-06 07:54:49 UTC
if a b value of 1 is passed to _imlib_Ellipse_DrawToData it will trigger a div by 0 will be triggered. No applications in SLED currently use this API as far as I can tell, conky and feh both only use the image loader api's. This could be triggered in a 3rd party and may be a potential DOS attack if the function parses user input.
Comment 2 Sebastian Krahmer 2016-04-11 07:59:29 UTC
CVE-2011-5326
Comment 3 Swamp Workflow Management 2016-04-11 22:00:12 UTC
bugbot adjusting priority
Comment 6 Swamp Workflow Management 2016-05-18 12:13:28 UTC
openSUSE-SU-2016:1330-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 963796,963797,963800,973759,973761,974202,974854,975703
CVE References: CVE-2011-5326,CVE-2014-9762,CVE-2014-9763,CVE-2014-9764,CVE-2014-9771,CVE-2016-3993,CVE-2016-3994,CVE-2016-4024
Sources used:
openSUSE 13.2 (src):    imlib2-1.4.9-17.4.1
Comment 7 Swamp Workflow Management 2016-06-03 11:09:11 UTC
SUSE-SU-2016:1481-1: An update that solves 5 vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 963797,963800,973759,973761,974202,977538
CVE References: CVE-2011-5326,CVE-2014-9763,CVE-2014-9764,CVE-2016-3993,CVE-2016-3994
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    imlib2-1.4.2-2.20.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    imlib2-1.4.2-2.20.1
Comment 8 Marguerite Su 2017-02-02 10:18:58 UTC
both releases for openSUSE/SUSE were made, I think this is a fixed bug that still leaves open. just occasionally be here when searching something on bugzilla.
Comment 9 Marcus Meissner 2017-02-02 10:35:07 UTC
it was overlook. closing