- Package:
- src:jbigkit
- Source:
- src:jbigkit
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2024-12-18 15:57:02 UTC
- Severity:
- normal
- Tags:
Hi, the following vulnerability was published for jbigkit. CVE-2017-9937[0]: | In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A | crafted TIFF document can lead to an abort resulting in a remote denial | of service attack. Note, that originally the issue has been reported for LibTIFF project, [1], but as shown in [2] the issue lies in jbigkit itself. It can be seen either with an ASAN build, or under valgrind: ==10811== Memcheck, a memory error detector ==10811== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al. ==10811== Using Valgrind-3.12.0 and LibVEX; rerun with -h for copyright info ==10811== Command: ./jbigkit-2.1/pbmtools/jbgtopbm ./poc2_only_jbig_content ==10811== ==10811== ==10811== Process terminating with default action of signal 6 (SIGABRT) ==10811== at 0x5078FCF: raise (raise.c:51) ==10811== by 0x507A3F9: abort (abort.c:89) ==10811== by 0x4E3944C: ??? (in /usr/lib/x86_64-linux-gnu/libjbig.so.0) ==10811== by 0x4E3EB79: jbg_dec_in (in /usr/lib/x86_64-linux-gnu/libjbig.so.0) ==10811== by 0x109233: main (jbgtopbm.c:407) ==10811== ==10811== HEAP SUMMARY: ==10811== in use at exit: 17,192 bytes in 14 blocks ==10811== total heap usage: 15 allocs, 1 frees, 21,288 bytes allocated ==10811== ==10811== LEAK SUMMARY: ==10811== definitely lost: 0 bytes in 0 blocks ==10811== indirectly lost: 0 bytes in 0 blocks ==10811== possibly lost: 0 bytes in 0 blocks ==10811== still reachable: 17,192 bytes in 14 blocks ==10811== suppressed: 0 bytes in 0 blocks ==10811== Rerun with --leak-check=full to see details of leaked memory ==10811== ==10811== For counts of detected and suppressed errors, rerun with: -v ==10811== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0) Aborted If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2017-9937 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9937 [1] http://bugzilla.maptools.org/show_bug.cgi?id=2707 [2] http://bugzilla.maptools.org/show_bug.cgi?id=2707#c8 Regards, Salvatore
Hey, I think this is a dup of the above bug. Thanks!
We believe that the bug you reported is fixed in the latest version of jbigkit, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 869708@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Michael van der Kolff <mvanderkolff@gmail.com> (supplier of updated jbigkit package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 3 Oct 2022 16:43:00 +1100 Source: jbigkit Architecture: source Version: 2.1-4 Distribution: unstable Urgency: medium Maintainer: Michael van der Kolff <mvanderkolff@gmail.com> Changed-By: Michael van der Kolff <mvanderkolff@gmail.com> Closes: 869708 969593 Changes: jbigkit (2.1-4) unstable; urgency=medium . * Use secure URI in Vcs control header (thanks, jelmer@!). * Add patch from upstream, closing serious bugs (Closes: #869708, #969593) * Bump Std-Vers to 4.6.1, no changes needed * Bump Compat to 12 - tests needed to be parallelisable * Fixed non-parallelised tests * Lintian-clean! Checksums-Sha1: 48244441ce5a73409ec10b8c25e9581c2e68717b 1950 jbigkit_2.1-4.dsc 826305dc925b1d36c52e8b5705b5df8fe41f1a79 8076 jbigkit_2.1-4.debian.tar.xz 03071e4d26c682029ac52d520fc461b70d9d1b96 6152 jbigkit_2.1-4_source.buildinfo Checksums-Sha256: 8f80892d516f344b7d09402124aef3cacc21219437725c8b54c439a256d20b92 1950 jbigkit_2.1-4.dsc 24f996ae16383125e6cea7f3f687d6c50b8e5335f2e9b4b1728e9be1bcad2600 8076 jbigkit_2.1-4.debian.tar.xz 98def097d524d589417bf41f79ed85b401e4d0cdc0641660be6efd5af35fd6a6 6152 jbigkit_2.1-4_source.buildinfo Files: 370881c3ea23de2b3f7eb145c9c6189c 1950 libs optional jbigkit_2.1-4.dsc a91eb14db479f5c12413972d057833ec 8076 libs optional jbigkit_2.1-4.debian.tar.xz afa4d36ce2d8a875ce0106a9d6f1bca1 6152 libs optional jbigkit_2.1-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEaTNn/67NjqrNHwY7AXHhgorgk0UFAmM6hSsACgkQAXHhgorg k0U8cw/9FZeR6DPlxsh4fsClMtyAYd05pCPWi8wz9EnvEr/J6rpA6OSTQhDWn7kN eDx3Dz4crfHEFYFmGXOQWYaE/4TES4vWSBr5iuYcjm+E03O7XG91EXqgM9CjAgzI 9PlRSJczxkN/bk4buqOYCPh7zgJ4q0L6ZIeYDBtXCT3dlqtYv5XaKLiJXnqHAenz dqbMipAKSwThw572xktpGJJltrccV5jJje/H2wffvLiOGohaxiuuFoJ746GLyOpF bdz3XA1mS6eOr8PPmqvBovbMJ+cOpsczumt6q5avoc54gE3umo2HZZ2g0JVdCcu7 8tfeV9l0F4UO9SynN5flPvUAXfT5ft6K7BAjSd0HllebNQCJ2g4JPDHT/SCkNAT6 +RjoPYsw4akl5sDx3uprgfKvwPfl0hIJZXWuir4iW8WpEZgkaYWwFG7xpdRA/HmK F0+oTKoi680tm5Sg1LNRL9yo4nmCc4BNG3lT2FGFTCkBC9pyvHxeKolZ+CgsIM8j dp4dSBmStAOtasuls5NtxacrQ6TfWisiRbsLjwLiAidyKpvOSv1T004V7HUkHp3A KMK44ciINyTnug8XLJCdH5aRn0KLsyLm81mq0TIsDOz96WmfpBXygKeJ3YBeSUXQ gueWMMchXrxVx04fKZt+di1wxik7SynKmERvsijmoEe5AVC2dxo= =rHNr -----END PGP SIGNATURE-----
On Mon, 3 Oct 2022 12:47:42 +1100 Michael van der Kolff <mvanderkolff@gmail.com> wrote: > Hey, > > I think this is a dup of the above bug. > > Thanks! > > --Michael Hi, This was a different vulnerability than bug #969593 Ubuntu has been patching CVE-2017-9937 downstream. Attaching a debdiff to propose the same patch in debian.