Hi, The following vulnerabilities were published for gegl. CVE-2018-10111[0]: | An issue was discovered in GEGL through 0.3.32. The render_rectangle | function in process/gegl-processor.c has unbounded memory allocation, | leading to a denial of service (application crash) upon allocation | failure. https://bugzilla.gnome.org/show_bug.cgi?id=795249 https://gitlab.gnome.org/GNOME/gegl/issues/65 POC https://github.com/xiaoqx/pocs/tree/master/gegl#2-gegl-dos-1 CVE-2018-10112[1]: | An issue was discovered in GEGL through 0.3.32. The | gegl_tile_backend_swap_constructed function in buffer/gegl-tile- | backend-swap.c allows remote attackers to cause a denial of service | (write access violation) or possibly have unspecified other impact via | a malformed PNG file that is mishandled during a call to the | babl_format_get_bytes_per_pixel function in babl-format.c in babl | 0.1.46. https://bugzilla.gnome.org/show_bug.cgi?id=795249 https://gitlab.gnome.org/GNOME/gegl/issues/65 https://github.com/xiaoqx/pocs/tree/master/gegl#4-gegl-outbound-write-2 If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2018-10111 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10111 [1] https://security-tracker.debian.org/tracker/CVE-2018-10112 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10112 Please adjust the affected versions in the BTS as needed.
I'm closing since this is fixed in Stable and more recent and it's listed as "no DSA, ignored" at https://security-tracker.debian.org/tracker/source-package/gegl Thank you, Jeremy Bicha
Am Mon, Jul 11, 2022 at 09:30:56AM +0200 schrieb Jeremy Bicha:
Why do you believe 0.3.34 is fixed? The Gitlab issue referenced
still shows it as unfixed?
Cheers,
Moritz
Control: reopen -1 Control: found -1 0.3.34-1 I apologize. I only read the short description provided in the email which suggested to me that the bug was fixed in 0.3.32. Reopening now. Thank you, Jeremy Bicha
Upstream has closed this issue as unreproducible, so I'm also closing the Debian bug. https://gitlab.gnome.org/GNOME/gegl/-/work_items/65 Thank you, Jeremy Bícha