Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-1000126, 127, 128: multiple memory safety issues #174

Closed
anarcat opened this issue Nov 23, 2017 · 5 comments
Closed

CVE-2017-1000126, 127, 128: multiple memory safety issues #174

anarcat opened this issue Nov 23, 2017 · 5 comments
Milestone

Comments

@anarcat
Copy link

anarcat commented Nov 23, 2017

In this discussion, three CVE identifiers were assigned to exiv2 and they do not seem to be documented here. Those are:

  • CVE-2017-1000126 - exiv2 0.26 contains a Stack out of bounds read in webp parser
  • CVE-2017-1000127 - Exiv2 0.26 contains a heap buffer overflow in tiff parser
  • CVE-2017-1000128 - Description | Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser

All three are triggered by afl when exiv is compiled with ASAN.

@anarcat
Copy link
Author

anarcat commented Nov 23, 2017

Note that I cannot reproduce those issues in a Debian "wheezy" environment (exiv2 0.23) without ASAN, but running under valgrind, which sometimes reproduces ASAN issues.

@carnil
Copy link

carnil commented Nov 23, 2017

@anarcat I think it would be more ideal to track the three individual issues with three bugs, can you split them up per CVE?

@anarcat
Copy link
Author

anarcat commented Nov 23, 2017

sure, will do.

@anarcat
Copy link
Author

anarcat commented Nov 23, 2017

i filed #175, #176 and #177 to followup on the issues individually. apologies for the copy-pasted summary, but i didn't know what else to put in there. :p

@anarcat anarcat closed this as completed Nov 23, 2017
@piponazo
Copy link
Collaborator

Thanks for creating those detailed issues. We will take care of them :)

@clanmills clanmills added this to the v0.27 milestone Nov 8, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants