Bug 851064 (CVE-2013-4589) - VUL-1: CVE-2013-4589: GraphicsMagick: denial of service The vulnerability is caused due to an error within the "ExportAlphaQuantumType()"
Summary: VUL-1: CVE-2013-4589: GraphicsMagick: denial of service The vulnerability is...
Status: RESOLVED FIXED
Alias: CVE-2013-4589
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:RedHat:CVE-2013-4589:4.3:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-19 09:52 UTC by Victor Pereira
Modified: 2016-08-01 14:44 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
patch against GraphicsMagick 1.2.5 (699 bytes, patch)
2013-11-21 10:03 UTC, Petr Gajdos
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-11-19 09:52:10 UTC
CVE-2013-4589

GraphicsMagick, a comprehensive image processing package, is found to have a vulnerability which can be exploited by malicious people to cause a Denial of Service (DoS).

The vulnerability is caused due to an error within the "ExportAlphaQuantumType()" function found in magick/export.c when exporting 8-bit RGBA images, which can be exploited to cause a crash.

The vulnerability is reported in versions prior to 1.3.18, Fedora 19 already ships with 1.3.18, so it doesn't seem to be affected.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4589
https://bugzilla.redhat.com/show_bug.cgi?id=1019085
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=729661
https://bugs.gentoo.org/show_bug.cgi?id=488050
https://secunia.com/advisories/55288/
http://comments.gmane.org/gmane.comp.security.oss.general/11502
Comment 1 Swamp Workflow Management 2013-11-19 23:00:19 UTC
bugbot adjusting priority
Comment 2 Petr Gajdos 2013-11-21 10:01:45 UTC
Affected: 12.3, 12.2, sles11. 

In all versions (a) we have GraphicsMagick <= 1.3.17 (b) we are building with quantum depth 8.
Comment 3 Petr Gajdos 2013-11-21 10:03:02 UTC
Created attachment 568467 [details]
patch against GraphicsMagick 1.2.5
Comment 4 Thomas Biege 2014-01-09 16:01:29 UTC
CVE-2013-4589: CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:N/A:P): Insufficient Information (CWE-noinfo)
Comment 6 Petr Gajdos 2016-05-30 15:03:56 UTC
Package submitted.
Comment 7 Swamp Workflow Management 2016-06-17 16:08:25 UTC
SUSE-SU-2016:1614-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 851064,965574,982178
CVE References: CVE-2013-4589,CVE-2015-8808,CVE-2016-5118
Sources used:
SUSE Studio Onsite 1.3 (src):    GraphicsMagick-1.2.5-4.38.1
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    GraphicsMagick-1.2.5-4.38.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    GraphicsMagick-1.2.5-4.38.1
Comment 8 Marcus Meissner 2016-08-01 14:44:26 UTC
released