Bug 1021517 (CVE-2016-8710) - VUL-0: CVE-2016-8710: libbpg: Image Decoding Code Execution [TALOS-2016-0223]
Summary: VUL-0: CVE-2016-8710: libbpg: Image Decoding Code Execution [TALOS-2016-0223]
Status: RESOLVED WONTFIX
Alias: CVE-2016-8710
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Luigi Baldoni
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-23 22:21 UTC by Mikhail Kasimov
Modified: 2017-02-06 17:46 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Kasimov 2017-01-23 22:21:41 UTC
Refs:
=================================================================================
[1] http://blog.talosintel.com/2017/01/vulnerability-spotlight-libbpg-image.html (Vulnerability Spotlight - LibBPG Image Decoding Code Execution)

[2] http://www.talosintelligence.com/reports/TALOS-2016-0223/ (Libbpg BGP image decoding Code Execution Vulnerability)
=================================================================================

[1]  Known vulnerable versions:
Libbpg - 0.9.4 and 0.9.7 

https://software.opensuse.org/package/libbpg -- TW, 42.1|2, 13.2: 0.9.7.

BPG Specification: http://bellard.org/bpg/bpg_spec.txt

[2] Technical details (Crash Information chapter) and patch info (Mitigation chapter). In particular, pay, please, attention here on phrase -- "The following patch will fix the vulnerability, but it is untested as to whether it breaks any legitimate images."
Comment 1 Swamp Workflow Management 2017-01-23 23:00:57 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2017-01-24 09:57:34 UTC
only in graphics/libbpg
Comment 3 Matthias Gerstner 2017-01-24 10:29:19 UTC
As Marcus already noted libbpg is only existing in the graphics/libbpg devel
package, not part of any openSUSE version. This will not be maintained by us.
You may fix the bug, however, on your own devices.
Comment 4 Luigi Baldoni 2017-01-24 11:30:57 UTC
Author contacted, waiting for an official statement.
Comment 5 Luigi Baldoni 2017-02-06 17:32:47 UTC
Update: the author writes that he's not going to address the problem for the time being.

Secondly, the patch itself appears to be a backport from the official libavcodec, but once applied, libbpg doesn't build anymore.

If the reporter or anyone else wishes to give it a try, they're very welcome to.

Regards
Comment 6 Luigi Baldoni 2017-02-06 17:46:18 UTC
WONTFIX