Re: Gentoo ImageMagick BMP image buffer overflow

Bob Friesenhahn <[email protected]> Thu, 9 Sep 2004 11:46:10 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Thu, 9 Sep 2004, Albert Chin wrote:

> Is GM also vulnerable:
>  http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml
>  http://studio.imagemagick.org/pipermail/magick-developers/2004-August/002011.html

Yes, GM is also vulnerable.  Glenn Randers-Pehrson checked fixes into 
both the CVS development version, and into the 1.1 branch on August 
24.

I also noticed a potential stack buffer overflow issue in tiff.c, 
which is fixed in both stable and development branches.

Bob
======================================
Bob Friesenhahn
[email protected]
http://www.simplesystems.org/users/bfriesen


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM. 
Deadline: Sept. 13. Go here: http://sf.net/ppc_contest.php