CVE-2016-8678: Q64 version heap-based buffer overflow in IsPixelMonochrome

Related Vulnerabilities: CVE-2016-8678  

Debian Bug report logs - #845204
CVE-2016-8678: Q64 version heap-based buffer overflow in IsPixelMonochrome

version graph

Reported by: Bastien ROUCARIES <roucaries.bastien@gmail.com>

Date: Mon, 21 Nov 2016 12:48:02 UTC

Severity: minor

Tags: fixed-upstream, patch, security, wontfix

Found in versions imagemagick/8:6.7.7.10-5+deb7u7, imagemagick/8:6.7.7.10-5, imagemagick/8:6.9.6.2+dfsg-2, imagemagick/8:6.7.7.10-4, imagemagick/8:6.8.9.9-5+deb8u5

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, secure-testing-team@lists.alioth.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#845204; Package src:imagemagick. (Mon, 21 Nov 2016 12:48:04 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien ROUCARIES <roucaries.bastien@gmail.com>:
New Bug report received and forwarded. Copy sent to secure-testing-team@lists.alioth.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Mon, 21 Nov 2016 12:48:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Bastien ROUCARIES <roucaries.bastien@gmail.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2016-8678: heap-based buffer overflow in IsPixelMonochrome
Date: Mon, 21 Nov 2016 13:44:27 +0100
Package: src:imagemagick
version: 8:6.9.6.2+dfsg-2
Severity: important
Tags: patch security
X-Debbugs-CC: secure-testing-team@lists.alioth.debian.org
control: found -1 8:6.7.7.10-5+deb7u7
control: found -1 8:6.8.9.9-5+deb8u5
control: tags -1 + fixed-upstream



Marked as found in versions imagemagick/8:6.7.7.10-5+deb7u7. Request was from Bastien ROUCARIES <roucaries.bastien@gmail.com> to submit@bugs.debian.org. (Mon, 21 Nov 2016 12:48:04 GMT) (full text, mbox, link).


Marked as found in versions imagemagick/8:6.8.9.9-5+deb8u5. Request was from Bastien ROUCARIES <roucaries.bastien@gmail.com> to submit@bugs.debian.org. (Mon, 21 Nov 2016 12:48:05 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream. Request was from Bastien ROUCARIES <roucaries.bastien@gmail.com> to submit@bugs.debian.org. (Mon, 21 Nov 2016 12:48:05 GMT) (full text, mbox, link).


Marked as found in versions imagemagick/8:6.7.7.10-5. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 21 Nov 2016 13:21:06 GMT) (full text, mbox, link).


Marked as found in versions imagemagick/8:6.7.7.10-4. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 21 Nov 2016 19:09:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#845204; Package src:imagemagick. (Fri, 25 Nov 2016 13:03:21 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien ROUCARIES <roucaries.bastien@gmail.com>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Fri, 25 Nov 2016 13:03:21 GMT) (full text, mbox, link).


Message #20 received at 845204@bugs.debian.org (full text, mbox, reply):

From: Bastien ROUCARIES <roucaries.bastien@gmail.com>
To: 845204@bugs.debian.org
Subject: Wont fix
Date: Fri, 25 Nov 2016 14:01:55 +0100
control: severity -1 minor
control: tags -1 + wontfix

This bug concern only Q64 that is not compiled on debian and does not
work on the upstream side.

Bastien



Severity set to 'minor' from 'important' Request was from Bastien ROUCARIES <roucaries.bastien@gmail.com> to 845204-submit@bugs.debian.org. (Fri, 25 Nov 2016 13:03:21 GMT) (full text, mbox, link).


Added tag(s) wontfix. Request was from Bastien ROUCARIES <roucaries.bastien@gmail.com> to 845204-submit@bugs.debian.org. (Fri, 25 Nov 2016 13:03:21 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#845204; Package src:imagemagick. (Thu, 13 Jul 2017 16:00:06 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien ROUCARIÈS <roucaries.bastien+debian@gmail.com>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Thu, 13 Jul 2017 16:00:06 GMT) (full text, mbox, link).


Message #29 received at 845204@bugs.debian.org (full text, mbox, reply):

From: Bastien ROUCARIÈS <roucaries.bastien+debian@gmail.com>
To: 845204@bugs.debian.org
Subject: retitle
Date: Thu, 13 Jul 2017 17:52:55 +0200
[Message part 1 (text/plain, inline)]
retitle -1 CVE-2016-8678: Q64 version heap-based buffer overflow in IsPixelMonochrome
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#845204; Package src:imagemagick. (Thu, 13 Jul 2017 16:15:03 GMT) (full text, mbox, link).


Acknowledgement sent to Bastien ROUCARIÈS <roucaries.bastien+debian@gmail.com>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Thu, 13 Jul 2017 16:15:03 GMT) (full text, mbox, link).


Message #34 received at 845204@bugs.debian.org (full text, mbox, reply):

From: Bastien ROUCARIÈS <roucaries.bastien+debian@gmail.com>
To: 845204@bugs.debian.org
Subject: retitle
Date: Thu, 13 Jul 2017 18:10:32 +0200
control: retitle -1 CVE-2016-8678: Q64 version heap-based buffer overflow in IsPixelMonochrome



Changed Bug title to 'CVE-2016-8678: Q64 version heap-based buffer overflow in IsPixelMonochrome' from 'CVE-2016-8678: heap-based buffer overflow in IsPixelMonochrome'. Request was from Bastien ROUCARIÈS <roucaries.bastien+debian@gmail.com> to 845204-submit@bugs.debian.org. (Thu, 13 Jul 2017 16:15:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:10:19 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.