#869708 jbigkit: CVE-2017-9937

Package:
src:jbigkit
Source:
src:jbigkit
Submitter:
Salvatore Bonaccorso
Date:
2024-12-18 15:57:02 UTC
Severity:
normal
Tags:
#869708#5
Date:
2017-07-25 20:28:26 UTC
From:
To:
Hi,

the following vulnerability was published for jbigkit.

CVE-2017-9937[0]:
| In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A
| crafted TIFF document can lead to an abort resulting in a remote denial
| of service attack.

Note, that originally the issue has been reported for LibTIFF project,
[1], but as shown in [2] the issue lies in jbigkit itself. It can be
seen either with an ASAN build, or under valgrind:

==10811== Memcheck, a memory error detector
==10811== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al.
==10811== Using Valgrind-3.12.0 and LibVEX; rerun with -h for copyright info
==10811== Command: ./jbigkit-2.1/pbmtools/jbgtopbm ./poc2_only_jbig_content
==10811==
==10811==
==10811== Process terminating with default action of signal 6 (SIGABRT)
==10811==    at 0x5078FCF: raise (raise.c:51)
==10811==    by 0x507A3F9: abort (abort.c:89)
==10811==    by 0x4E3944C: ??? (in /usr/lib/x86_64-linux-gnu/libjbig.so.0)
==10811==    by 0x4E3EB79: jbg_dec_in (in /usr/lib/x86_64-linux-gnu/libjbig.so.0)
==10811==    by 0x109233: main (jbgtopbm.c:407)
==10811==
==10811== HEAP SUMMARY:
==10811==     in use at exit: 17,192 bytes in 14 blocks
==10811==   total heap usage: 15 allocs, 1 frees, 21,288 bytes allocated
==10811==
==10811== LEAK SUMMARY:
==10811==    definitely lost: 0 bytes in 0 blocks
==10811==    indirectly lost: 0 bytes in 0 blocks
==10811==      possibly lost: 0 bytes in 0 blocks
==10811==    still reachable: 17,192 bytes in 14 blocks
==10811==         suppressed: 0 bytes in 0 blocks
==10811== Rerun with --leak-check=full to see details of leaked memory
==10811==
==10811== For counts of detected and suppressed errors, rerun with: -v
==10811== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0)
Aborted
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9937
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9937
[1] http://bugzilla.maptools.org/show_bug.cgi?id=2707
[2] http://bugzilla.maptools.org/show_bug.cgi?id=2707#c8

Regards,
Salvatore

#869708#10
Date:
2022-10-03 01:47:42 UTC
From:
To:
Hey,

I think this is a dup of the above bug.

Thanks!

#869708#15
Date:
2022-10-03 07:04:21 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
jbigkit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 869708@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael van der Kolff <mvanderkolff@gmail.com> (supplier of updated jbigkit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 3 Oct 2022 16:43:00 +1100
Source: jbigkit
Architecture: source
Version: 2.1-4
Distribution: unstable
Urgency: medium
Maintainer: Michael van der Kolff <mvanderkolff@gmail.com>
Changed-By: Michael van der Kolff <mvanderkolff@gmail.com>
Closes: 869708 969593
Changes:
 jbigkit (2.1-4) unstable; urgency=medium
 .
   * Use secure URI in Vcs control header (thanks, jelmer@!).
   * Add patch from upstream, closing serious bugs (Closes: #869708, #969593)
   * Bump Std-Vers to 4.6.1, no changes needed
   * Bump Compat to 12 - tests needed to be parallelisable
   * Fixed non-parallelised tests
   * Lintian-clean!
Checksums-Sha1:
 48244441ce5a73409ec10b8c25e9581c2e68717b 1950 jbigkit_2.1-4.dsc
 826305dc925b1d36c52e8b5705b5df8fe41f1a79 8076 jbigkit_2.1-4.debian.tar.xz
 03071e4d26c682029ac52d520fc461b70d9d1b96 6152 jbigkit_2.1-4_source.buildinfo
Checksums-Sha256:
 8f80892d516f344b7d09402124aef3cacc21219437725c8b54c439a256d20b92 1950 jbigkit_2.1-4.dsc
 24f996ae16383125e6cea7f3f687d6c50b8e5335f2e9b4b1728e9be1bcad2600 8076 jbigkit_2.1-4.debian.tar.xz
 98def097d524d589417bf41f79ed85b401e4d0cdc0641660be6efd5af35fd6a6 6152 jbigkit_2.1-4_source.buildinfo
Files:
 370881c3ea23de2b3f7eb145c9c6189c 1950 libs optional jbigkit_2.1-4.dsc
 a91eb14db479f5c12413972d057833ec 8076 libs optional jbigkit_2.1-4.debian.tar.xz
 afa4d36ce2d8a875ce0106a9d6f1bca1 6152 libs optional jbigkit_2.1-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEaTNn/67NjqrNHwY7AXHhgorgk0UFAmM6hSsACgkQAXHhgorg
k0U8cw/9FZeR6DPlxsh4fsClMtyAYd05pCPWi8wz9EnvEr/J6rpA6OSTQhDWn7kN
eDx3Dz4crfHEFYFmGXOQWYaE/4TES4vWSBr5iuYcjm+E03O7XG91EXqgM9CjAgzI
9PlRSJczxkN/bk4buqOYCPh7zgJ4q0L6ZIeYDBtXCT3dlqtYv5XaKLiJXnqHAenz
dqbMipAKSwThw572xktpGJJltrccV5jJje/H2wffvLiOGohaxiuuFoJ746GLyOpF
bdz3XA1mS6eOr8PPmqvBovbMJ+cOpsczumt6q5avoc54gE3umo2HZZ2g0JVdCcu7
8tfeV9l0F4UO9SynN5flPvUAXfT5ft6K7BAjSd0HllebNQCJ2g4JPDHT/SCkNAT6
+RjoPYsw4akl5sDx3uprgfKvwPfl0hIJZXWuir4iW8WpEZgkaYWwFG7xpdRA/HmK
F0+oTKoi680tm5Sg1LNRL9yo4nmCc4BNG3lT2FGFTCkBC9pyvHxeKolZ+CgsIM8j
dp4dSBmStAOtasuls5NtxacrQ6TfWisiRbsLjwLiAidyKpvOSv1T004V7HUkHp3A
KMK44ciINyTnug8XLJCdH5aRn0KLsyLm81mq0TIsDOz96WmfpBXygKeJ3YBeSUXQ
gueWMMchXrxVx04fKZt+di1wxik7SynKmERvsijmoEe5AVC2dxo=
=rHNr
-----END PGP SIGNATURE-----

#869708#28
Date:
2024-12-18 15:52:21 UTC
From:
To:
On Mon, 3 Oct 2022 12:47:42 +1100 Michael van der Kolff  <mvanderkolff@gmail.com> wrote:

  > Hey,
  >
  > I think this is a dup of the above bug.
  >
  > Thanks!
  >
  > --Michael

Hi,

This was a different vulnerability than bug #969593

Ubuntu has been patching CVE-2017-9937 downstream.

Attaching a debdiff to propose the same patch in debian.