#1036999 imagemagick: CVE-2023-34151

Package:
src:imagemagick
Source:
src:imagemagick
Submitter:
Salvatore Bonaccorso
Date:
2024-02-23 17:36:07 UTC
Severity:
normal
Tags:
#1036999#5
Date:
2023-05-31 20:14:54 UTC
From:
To:
Hi,

The following vulnerability was published for imagemagick.

CVE-2023-34151[0]:
| A vulnerability was found in ImageMagick. This security flaw ouccers
| as an undefined behaviors of casting double to size_t in svg, mvg and
| other coders (recurring bugs of CVE-2022-32546).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-34151
https://www.cve.org/CVERecord?id=CVE-2023-34151
[1] https://github.com/ImageMagick/ImageMagick/issues/6341

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1036999#14
Date:
2024-02-23 15:02:55 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1036999@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastien Roucariès <rouca@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 17 Feb 2024 15:31:24 +0000
Source: imagemagick
Architecture: source
Version: 8:6.9.11.60+dfsg-1.3+deb11u3
Distribution: bullseye-security
Urgency: medium
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Closes: 1013282 1036999
Changes:
 imagemagick (8:6.9.11.60+dfsg-1.3+deb11u3) bullseye-security; urgency=medium
 .
   * Fix CVE-2021-3610 heap buffer overflow vulnerability in TIFF coder
   * Fix an heap buffer overflow in TIFF coder
   * Fix uninitialised value passing in TIFFGetField
   * Fix stack overflow in TIFF coder
   * Early exit in case of malformed TIFF file
   * Fix buffer overrun in TIFF coder
   * Fix unitialised value in TIFF coder
   * Fix CVE-2022-1115: Heap based overflow in
     TIFF coder (Closes: #1013282)
   * Fix uninitialised value in TIFF coders
   * Use salsa-ci
   * Fix CVE-2023-1289: A specially created SVG file loaded itself and
     causes a segmentation fault. This flaw allows a remote attacker
     to pass a specially crafted SVG file that leads to a segmentation
     fault, generating many trash files in "/tmp," resulting in
     a denial of service. When ImageMagick crashes,
     it generates a lot of trash files. These trash files
     can be large if the SVG file contains many render actions.
     In a denial of service attack, if a remote attacker uploads an SVG file
     of size t, ImageMagick generates files of size 103*t.
     If an attacker uploads a 100M SVG, the server will generate about 10G.
   * Fix CVE-2023-1906: A heap-based buffer overflow issue was
     discovered in ImageMagick's ImportMultiSpectralQuantum() function
     in MagickCore/quantum-import.c. An attacker could pass specially
     crafted file to convert, triggering an out-of-bounds read error,
     allowing an application to crash, resulting in a denial of service.
   * Fix CVE-2023-34151: Imagemagick was vulnerable due to
     an undefined behaviors of casting double to size_t in svg, mvg
     and other coders. (Closes: #1036999)
   * Fix CVE-2023-3428: A heap-based buffer overflow vulnerability
     was found in coders/tiff.c in ImageMagick. This issue
     may allow a local attacker to trick the user into opening
     a specially crafted file, resulting in an application crash
     and denial of service.
   * Fix CVE-2023-5341: A heap use-after-free flaw was found in
     coders/bmp.c
Checksums-Sha1:
 be11a2c206a17c86362b39985ab168010e4af271 5131 imagemagick_6.9.11.60+dfsg-1.3+deb11u3.dsc
 ef515de6277141ee73ec6de5730ed23d71a266d9 263996 imagemagick_6.9.11.60+dfsg-1.3+deb11u3.debian.tar.xz
 cc9a5e3894f2b99a719f175514e39e64393b202c 30930 imagemagick_6.9.11.60+dfsg-1.3+deb11u3_amd64.buildinfo
Checksums-Sha256:
 c5c87b8bde9f0737ba3751d8dde5b7dede10019038690b03b11e331568cfa02e 5131 imagemagick_6.9.11.60+dfsg-1.3+deb11u3.dsc
 cb1f7ee1bd082f28b36b4db6a9eb9e5e04d92a5514e0aac14727f2378eb9a2ae 263996 imagemagick_6.9.11.60+dfsg-1.3+deb11u3.debian.tar.xz
 630ae106eedb7718cb6faeec92763811296912eaa4b6d16c9470c5a025dc413c 30930 imagemagick_6.9.11.60+dfsg-1.3+deb11u3_amd64.buildinfo
Files:
 4bd2d05d79f290d0dd0b6f2bc9e3d336 5131 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u3.dsc
 c39087eecf2c3e1fa259f9d200e6eb65 263996 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u3.debian.tar.xz
 3adf9c61d5a8f1a031b2b4628fd2f2ce 30930 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmXSPVMRHHJvdWNhQGRl
Ymlhbi5vcmcACgkQADoaLapBCF8OXw/9H390//Zc2A1LR9XQS3gBIOJYTTx96upi
8tcwRUjH2M5gERkY/f24bfNnvOskVmZGWfkx9qdQPLvZBtoWalUcGzIzBBIRcqQo
ZaFTsOX0V3tYd8rE5I+lD6a2aN6h26uMIvNul11rnXIfDn6tXOUX9QqipbnC885U
DmcsV5OpY2waeOBxMQmQHAVXcAvVz8Ed+/PF4QzCetWUV/5koKzZQh76y1wQDxoL
cgCpu+omDSMIwD15zIJQF4j7Bg1JqgS2yaSr63ekr6ubnI3GBY/VcyVl8+01HacS
cj0XoNsmEwMDXy07Xbg0F6/PQnueYwzuIxQqXIH3P0arWR5WnrFFTiBBvtyqh37r
zG6K6AEaSxiQcPB4SgNvqrPMxr8yMjGOZnbsK64pkgRxTkZ+C1svQDbDJgE552bX
C1It8JI6aPRRk5g5QCRkqeNBv4Pt8IPRhfjB1Saw+NcacSgD5hjjIwP+L7aMCHOn
YUWSPJVH6MoYy9z3/FdkUVdpVSoDJUrw0P71nA4petT5UK3lRkTNoFZUEmwpWdjP
E1JjILzqCPAgheyKJTeIxsmovcEBaKDz4X2X10QVg1VtKCA+SYODE2rX1cDd+CWy
Q156t3xIO10tQ2HTzbL8+WfqYiPzGL7HcQI7il+wuhZwcj3x7WbC3+D4wC4zxC3Z
CcdGIX1hf1E=
=KILb
-----END PGP SIGNATURE-----

#1036999#19
Date:
2024-02-23 17:32:09 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1036999@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastien Roucariès <rouca@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 12 Feb 2024 20:15:47 +0000
Source: imagemagick
Architecture: source
Version: 8:6.9.11.60+dfsg-1.6+deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Closes: 1013282 1036999
Changes:
 imagemagick (8:6.9.11.60+dfsg-1.6+deb12u1) bookworm-security; urgency=high
 .
   * Acknowledge NMU
   * Fix CVE-2021-3610 heap buffer overflow vulnerability in TIFF coder
   * Fix an heap buffer overflow in TIFF coder
   * Fix uninitialised value passing in TIFFGetField
   * Fix stack overflow in TIFF coder
   * Early exit in case of malformed TIFF file
   * Fix buffer overrun in TIFF coder
   * Fix unitialised value in TIFF coder
   * Fix CVE-2022-1115: Heap based overflow in
     TIFF coder (Closes: #1013282)
   * Fix uninitialised value in TIFF coders
   * Use salsa-ci
   * Fix CVE-2023-1289: A specially created SVG file loaded itself and
     causes a segmentation fault. This flaw allows a remote attacker
     to pass a specially crafted SVG file that leads to a segmentation
     fault, generating many trash files in "/tmp," resulting in
     a denial of service. When ImageMagick crashes,
     it generates a lot of trash files. These trash files
     can be large if the SVG file contains many render actions.
     In a denial of service attack, if a remote attacker uploads an SVG file
     of size t, ImageMagick generates files of size 103*t.
     If an attacker uploads a 100M SVG, the server will generate about 10G.
   * Fix CVE-2023-1906: A heap-based buffer overflow issue was
     discovered in ImageMagick's ImportMultiSpectralQuantum() function
     in MagickCore/quantum-import.c. An attacker could pass specially
     crafted file to convert, triggering an out-of-bounds read error,
     allowing an application to crash, resulting in a denial of service.
   * Fix CVE-2023-34151: Imagemagick was vulnerable due to
     an undefined behaviors of casting double to size_t in svg, mvg
     and other coders. (Closes: #1036999)
   * Fix CVE-2023-3428: A heap-based buffer overflow vulnerability
     was found in coders/tiff.c in ImageMagick. This issue
     may allow a local attacker to trick the user into opening
     a specially crafted file, resulting in an application crash
     and denial of service.
   * Fix CVE-2023-5341: A heap use-after-free flaw was found in
     coders/bmp.c
Checksums-Sha1:
 6622115f5257a7e728056152f4b806b50c9a36ba 5131 imagemagick_6.9.11.60+dfsg-1.6+deb12u1.dsc
 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz
 099247f6a7601427b123abb75ff2f9895794ae57 264292 imagemagick_6.9.11.60+dfsg-1.6+deb12u1.debian.tar.xz
 96e9900a5dcc40ec1b7e34074c2c7ef1b81cd184 30898 imagemagick_6.9.11.60+dfsg-1.6+deb12u1_amd64.buildinfo
Checksums-Sha256:
 743092dc6ff5e41c150695215d1649557dcd5b7eac2ed4795ce5e7b4009a958f 5131 imagemagick_6.9.11.60+dfsg-1.6+deb12u1.dsc
 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz
 4ffc4f35cdf1a21e175d5e791c096767b4db12e2a00a335df2f7a615aa4d9141 264292 imagemagick_6.9.11.60+dfsg-1.6+deb12u1.debian.tar.xz
 9618fd0514f03af02d5e709a2ee7f8a1ec591f0e18b0764a5f5f87fd1e30042c 30898 imagemagick_6.9.11.60+dfsg-1.6+deb12u1_amd64.buildinfo
Files:
 b8185323af6c75536275a8d84f557fb6 5131 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u1.dsc
 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz
 7fa57d0d30392ec182249a5ac240b0fc 264292 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u1.debian.tar.xz
 21b5af2f739093766560be0091c35f27 30898 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmXPqzQRHHJvdWNhQGRl
Ymlhbi5vcmcACgkQADoaLapBCF+eWg/9EnzIP6+okBJab3hMFrU93UDpScGAeT3D
etohWACjZzFt2AQDgEomCWXqAAB0+96Px8OdjJjZa8gPEbvts4oXN7gNpPzK/4n/
F1w1RvU5VTkJ5xLtJI3KBVi7Ojc+H7z0kh92onelXEWv2xFlKR2VWfFixSHmLAMt
IXCRP+uePzUFSOBBHmnf+v+yEgvWi+WHOPZDU+fZNcwRQg6GRdG3JUFakC+k0bd5
JUkSNMr1FQW8tVrGCMBQ/aOuvStT174rAgSqLh8CkoPOb6Ab/uD6is735C71bFfT
hNPnW6mGfXrdiJwf+FAoQhzi/EBy31XTvxKd6asb3OA8dfOGrM7usf15mHIR8Qd9
VXdQ+OhKFRVi8XHXcTGogTQtwcA8Y1qwUe9OzHHMMCaCYq8hvArd1RjdXAmFetjU
eF6QVvFX3hmKpzC3+NoOy3QUbJMnF8ByTfyGasZgB+cktsi/+ynpePG57itE+FEM
NSjT59be0Vyg6H1hvkQ3LUbTwWRkdp5qauAaTh6kDIJkuXTTDJlmn22P0pE8U7f3
pqNwQWv7mhQ/9FwuQWSLzgGk528gMIqbhhJR2uh+LywbyR9+z7jQ4zJSd6G03y2F
ABM4EVVYCOfx6T5WhirOCJfkvq5WSLwEbGLk0v/uRDmcJ1FcjAWnh5GmuiyG0P7u
r/QKX5YC4Os=
=ba+U
-----END PGP SIGNATURE-----