Bug 903638 (CVE-2014-8562) - VUL-0: CVE-2014-8562: ImageMagick: out-of-bounds memory error in DCM decode
Summary: VUL-0: CVE-2014-8562: ImageMagick: out-of-bounds memory error in DCM decode
Status: RESOLVED FIXED
Alias: CVE-2014-8562
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P5 - None : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/110367/
Whiteboard: maint:released:sle11-sp1:59862 maint...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-11-03 09:46 UTC by Johannes Segitz
Modified: 2014-12-15 10:15 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
POC image (18.72 KB, image/jpeg)
2014-11-03 09:46 UTC, Johannes Segitz
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-11-03 09:46:33 UTC
Created attachment 612158 [details]
POC image

Quote from https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=764872

The following command:

  convert test.jpg +profile '!icc,*' out.jpg

used to remove all image metadata except ICC tags/profiles.
However, in recent versions it just dies after exhausting all system memory.
Attaching a random sample image to test it.

Only OpenSUSE Factory and 13.2 are affected.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1159362
http://seclists.org/oss-sec/2014/q4/484
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-8562.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=764872
Comment 2 Petr Gajdos 2014-11-03 13:53:14 UTC
6.8.9-9, which claims to fix this, was submitted to Factory:

2014-10-03  6.8.9-9 Dirk Lemstra <dirk@snakeware...>
  [...]
  * Fixed buffer overflow in PCX and DCM coder (bug report from Hanno Böck).
  [...]
Comment 3 Petr Gajdos 2014-11-03 15:42:21 UTC
(In reply to Petr Gajdos from comment #1)
> Trying
> 
> http://trac.imagemagick.org/
> changeset?reponame=&new=16894%40ImageMagick%2Ftrunk%2Fcoders&old=16878%40Imag
> eMagick%2Ftrunk%2Fcoders

That's nonsense, sorry.
Comment 4 Petr Gajdos 2014-11-03 15:48:43 UTC
Hmm, CVE-2014-8562 doesn't exist on cve.mitre.org.

And I cannot reproduce the bug with ImageMagick-6.8.9.8-1.2.x86_64, what can I do wrongly?
Comment 5 Petr Gajdos 2014-11-04 07:49:17 UTC
Why do you think that debian bug in comment 0 relates to CVE-2014-8562?
Comment 8 Petr Gajdos 2014-11-04 12:11:38 UTC
All packages submitted I believe.
Comment 10 Swamp Workflow Management 2014-11-12 10:05:17 UTC
openSUSE-SU-2014:1396-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562
Sources used:
openSUSE 13.2 (src):    ImageMagick-6.8.9.8-4.1
openSUSE 13.1 (src):    ImageMagick-6.8.6.9-2.24.1
openSUSE 12.3 (src):    ImageMagick-6.7.8.8-4.17.1
Comment 11 Johannes Segitz 2014-11-13 11:16:38 UTC
(In reply to Petr Gajdos from comment #5)
Nothing, sorry. As you already discovered, this was reported in 
http://seclists.org/fulldisclosure/2014/Nov/1
The subject states 
Three out of bounds access issues in ImageMagick (CVE-2014-8354, CVE-2014-8355, CVE-2014-8562)
but then in the text for the first and the third issue CVE-2014-8354 is used. I will go through all ImageMagick submits today and check that we have everthing that we need in there.
Comment 14 Petr Gajdos 2014-11-14 11:41:13 UTC
.
Comment 16 Swamp Workflow Management 2014-12-08 16:07:38 UTC
SUSE-SU-2014:1595-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638,905260
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562,CVE-2014-8716
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Software Development Kit 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Server 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Desktop 12 (src):    ImageMagick-6.8.8.1-8.2
Comment 17 Swamp Workflow Management 2014-12-13 05:05:15 UTC
SUSE-SU-2014:1631-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638,905260
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562,CVE-2014-8716
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Server 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
Comment 18 Marcus Meissner 2014-12-15 10:13:39 UTC
released