mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-29 13:31:43 -09:00
This package’s last release dates back to July 2018. Since then, a
number of CVEs have accumulated. This patch applies several
vulnerability fixes from the Fedora project. Not all vulnerabilities are
addressed by this patch.
- CVE-2019-12211
When FreeImage 3.18.0 reads a tiff file, it will be handed to the
Load function of the PluginTIFF.cpp file, but a memcpy occurs in
which the destination address and the size of the copied data are
not considered, resulting in a heap overflow.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2019-12211
- CVE-2019-12213
When FreeImage 3.18.0 reads a special TIFF file, the
TIFFReadDirectory function in PluginTIFF.cpp always returns 1,
leading to stack exhaustion.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2019-12213
- CVE-2020-24292
Buffer Overflow vulnerability in load function in PluginICO.cpp in
FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary
code via opening of crafted ico file.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2020-24292
- https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
- CVE-2020-24293
Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp
in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary
code via opening of crafted psd file.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2020-24293
- https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
- CVE-2020-24295
Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in
FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary
code via use of crafted psd file.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2020-24295
- https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
- CVE-2021-33367
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker
to cause a denial of service via a crafted JXR file.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2021-33367
- https://sourceforge.net/p/freeimage/discussion/36109/thread/1a4db03d58/
- CVE-2021-40263
A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad
function in PluginTIFF.cpp.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2021-40263
- https://sourceforge.net/p/freeimage/bugs/336/
- CVE-2021-40266
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is
vulnerabile to null pointer dereference.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2021-40266
- https://sourceforge.net/p/freeimage/bugs/334/
- CVE-2023-47995
Memory Allocation with Excessive Size Value discovered in
BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0
allows attackers to cause a denial of service.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2023-47995
- CVE-2023-47997
An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in
FreeImage 3.18.0 leads to an infinite loop and allows attackers to
cause a denial of service.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2023-47997
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 6750719a20)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
26 lines
1.2 KiB
Diff
26 lines
1.2 KiB
Diff
CVE: CVE-2020-24295
|
|
Upstream: https://src.fedoraproject.org/rpms/freeimage/raw/rawhide/f/CVE-2020-24295.patch
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
diff -rupN a/Source/FreeImage/PSDParser.cpp b/Source/FreeImage/PSDParser.cpp
|
|
--- a/Source/FreeImage/PSDParser.cpp
|
|
+++ b/Source/FreeImage/PSDParser.cpp
|
|
@@ -1466,6 +1466,7 @@ FIBITMAP* psdParser::ReadImageData(FreeI
|
|
const unsigned dstBpp = (depth == 1) ? 1 : FreeImage_GetBPP(bitmap)/8;
|
|
const unsigned dstLineSize = FreeImage_GetPitch(bitmap);
|
|
BYTE* const dst_first_line = FreeImage_GetScanLine(bitmap, nHeight - 1);//<*** flipped
|
|
+ const unsigned dst_buffer_size = dstLineSize * nHeight;
|
|
|
|
BYTE* line_start = new BYTE[lineSize]; //< fileline cache
|
|
|
|
@@ -1481,6 +1482,9 @@ FIBITMAP* psdParser::ReadImageData(FreeI
|
|
const unsigned channelOffset = GetChannelOffset(bitmap, c) * bytes;
|
|
|
|
BYTE* dst_line_start = dst_first_line + channelOffset;
|
|
+ if (channelOffset + lineSize > dst_buffer_size) {
|
|
+ throw "Invalid PSD image";
|
|
+ }
|
|
for(unsigned h = 0; h < nHeight; ++h, dst_line_start -= dstLineSize) {//<*** flipped
|
|
io->read_proc(line_start, lineSize, 1, handle);
|
|
ReadImageLine(dst_line_start, line_start, lineSize, dstBpp, bytes);
|