Bugzilla – Bug 870855
VUL-0: CVE-2013-6369: jbigkit: buffer overflow
Last modified: 2014-09-01 10:03:00 UTC
via distros, embargoed, crd 20140408. From: Huzaifa Sidhpurwala <huzaifas@redhat.com> Date: Fri, 28 Mar 2014 14:00:30 +0530 Subject: ***UNCHECKED*** [vs-plain] jbigkit security issue All versions of JBIG-KIT released prior to version 2.1 contain a security vulnerability (buffer overflow) in the decoder implemented in the file jbig.c. This vulnerability might allow an attacker who can supply a specially crafted JBIG data stream to gain control over the receiving device or process. This issue was discovered by Florian Weimer of Red Hat Product Security Team. It was assigned CVE-2013-6369. Proposed un-embargo date is 20140408. If you need more information, mail me directly! -- Huzaifa Sidhpurwala / Red Hat Security Response Team
no internal maintainer. but is in SLE12-GA
bugbot adjusting priority
public now From: Huzaifa Sidhpurwala <huzaifas@redhat.com> Subject: [oss-security] jbigkit security flaw Date: Tue, 08 Apr 2014 18:37:34 +0530 Hi All, Florian Weimer of Red Hat Product Security Team found a stack-based buffer overflow flaw in the libjbig library (part of jbigkit). A specially-crafted image file read by libjbig could be used to cause a program linked to libjbig to crash or, potentially, to execute arbitrary code. This issue has been assigned CVE-2013-6369. References: https://bugzilla.redhat.com/show_bug.cgi?id=1032273 https://www.cl.cam.ac.uk/~mgk25/jbigkit/CHANGES -- Huzaifa Sidhpurwala / Red Hat Security Response Team
package updated https://build.opensuse.org/request/show/230099
I've asked for a new SR with a better description of the changes and the CVE noted.
Done.
Not fixed for SLE12 yet (Petr), also no openSUSE updates yet.
openSUSE: mr#242818
openSUSE-SU-2014:0978-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 870855 CVE References: CVE-2013-6369 Sources used: openSUSE 13.1 (src): jbigkit-2.0-10.4.1 openSUSE 12.3 (src): jbigkit-2.0-6.4.1
was released