Bug 977898 (CVE-2013-7455) - VUL-0: CVE-2013-7455: lcms2: double free on error recovering (VU#369800)
Summary: VUL-0: CVE-2013-7455: lcms2: double free on error recovering (VU#369800)
Status: RESOLVED FIXED
Alias: CVE-2013-7455
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/168493/
Whiteboard: CVSSv2:SUSE:CVE-2013-7455:6.8:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-04-29 20:44 UTC by Andreas Stieger
Modified: 2024-05-07 14:38 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2016-04-29 22:00:19 UTC
bugbot adjusting priority
Comment 2 Sebastian Krahmer 2016-05-03 09:07:51 UTC
Via CERT:

Hello folks,

Just a follow up on the last email notification about lcms2.

First, the proposed disclosure date for our vulnerability note is
indeed on Wednesday, MAY 4th, instead of March.

We have received a CVE identifier for this vulnerability:
CVE-2013-7455

For the record, regarding CVE and IDs for issues dislosed in prior
years, from MITRE:

>The year portion of a CVE ID should reflect when the existence of the
>issue, as a security vulnerability, first became public. Here, the
>commit message used the term "double free" and this is typically
>recognized as a type of error that may be exploitable. Thus, a
>CVE-2013-#### ID is preferable.


Finally, this email has a wide recipient list.  Just because your
organization is receiving this email, this does not necessarily mean
that we have evidence that your organization has a product that is
affected by this vulnerability.  We are simply notifying organizations
that may be affected.  If you have reasons why your organization is or
is not affected, please let us know and we can include this
information in the vulnerability note.

Surely this is preaching to the choir, but as with any library, ways
that an application can be affected include:

1) The library is installed system-wide and other applications use
this library.  The fix would be deployed via updating the system-wide
library.  A good number of apps appear to use lcms2 in this way.

2) The library is statically included in the application.  We've seen
a small number of apps, such as openjdk, openjpeg, and ghostscript use
lcms2 in this way.  We haven't seen any current app that uses this
method for utilizing lcms2 provide a vulnerable version of lcms2.  But
it's not out of the realm of possibility.

Once again, the patch is here:
<https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db#diff-189a94
+f0a7a47efdd43f5567e27a973b>
, and unless we hear some compelling reason to delay, we plan to
publish our vulnerability note on Wednesday, May 4th.


Thank you,
   Will Dormann
Comment 3 Marcus Meissner 2016-05-13 13:00:24 UTC
is public now.
Comment 4 Johannes Segitz 2018-02-16 12:57:47 UTC
Please submit for this. Thank you.
Comment 5 P Linnell 2018-02-17 03:04:08 UTC
Not sure this applies anymore. This applies to lcms2 2.5 release. Leap 42.2 had 2.7. 2.8 is in Leap 42.3.
Comment 6 Johannes Segitz 2018-02-19 09:21:45 UTC
(In reply to P Linnell from comment #5)
We have this in SUSE:SLE-12:Update and SUSE:SLE-11-SP3:Update
Comment 7 Johannes Segitz 2018-02-27 09:48:40 UTC
ping. Please submit
Comment 8 Johannes Segitz 2018-04-19 15:29:44 UTC
Assigning to SLE maintainer, please have a look
Comment 11 Stanislav Brabec 2018-05-30 15:00:01 UTC
Vulnerable versions are 2.5 and older.

We have no vulnerable version in openSUSE.

In SLE, we have vulnerable version in SUSE:SLE-12:Update (GA, and SP1, but not in SP2 nor SP3) and SUSE:SLE-11-SP3:Update.
Comment 12 Stanislav Brabec 2018-05-30 16:03:18 UTC
SUSE:SLE-12:Update: https://build.suse.de/request/show/165948
SUSE:SLE-11-SP3:Update: https://build.suse.de/request/show/165949
Comment 13 Stanislav Brabec 2018-05-30 16:05:25 UTC
Should be VU#369800 mentioned in the changes?
Comment 17 Thomas Leroy 2024-05-07 14:38:17 UTC
All done, closing.