Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-10-17 Thread Daniel Kobras
On Mon, Oct 16, 2006 at 10:41:25AM +0200, Martin Pitt wrote: > Daniel Kobras [2006-08-18 19:02 +0200]: > > --- imagemagick-6.2.4.5.dfsg1.orig/coders/sgi.c > > +++ imagemagick-6.2.4.5.dfsg1/coders/sgi.c > > @@ -171,13 +171,13 @@ > >q=pixels; > >if (bytes_per_pixel == 2) > > { > > -

Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-10-16 Thread Martin Pitt
Hi Daniel, Daniel Kobras [2006-08-18 19:02 +0200]: > --- imagemagick-6.2.4.5.dfsg1.orig/coders/sgi.c > +++ imagemagick-6.2.4.5.dfsg1/coders/sgi.c > @@ -171,13 +171,13 @@ >q=pixels; >if (bytes_per_pixel == 2) > { > - for (i=0; i < (long) width; ) > + for ( ; ; ) >{ >

Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-08-18 Thread Daniel Kobras
found 383314 6:6.0.6.2-2.6 thanks On Fri, Aug 18, 2006 at 07:02:01PM +0200, Daniel Kobras wrote: > On Wed, Aug 16, 2006 at 05:20:01PM +0200, Daniel Kobras wrote: > > On Wed, Aug 16, 2006 at 03:51:15PM +0200, Martin Pitt wrote: > > > http://www.overflow.pl/adv/imsgiheap.txt reported a buffer overfl

Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-08-18 Thread Daniel Kobras
tag 383314 + patch thanks On Wed, Aug 16, 2006 at 05:20:01PM +0200, Daniel Kobras wrote: > On Wed, Aug 16, 2006 at 03:51:15PM +0200, Martin Pitt wrote: > > http://www.overflow.pl/adv/imsgiheap.txt reported a buffer overflow in > > the SGI parser (demo exploit linked in the report). > > > > This h

Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-08-16 Thread Daniel Kobras
tags 383314 - patch clone 383314 -1 reassign -1 graphicsmagick retitle -1 libgraphicsmagick1: Buffer overflow in SGI parser [CVE-2006-4144] thanks On Wed, Aug 16, 2006 at 03:51:15PM +0200, Martin Pitt wrote: > http://www.overflow.pl/adv/imsgiheap.txt reported a buffer overflow in > the SGI parser

Bug#383314: libmagick9: Buffer overflow in SGI parser [CVE-2006-4144]

2006-08-16 Thread Martin Pitt
Package: libmagick9 Version: 6.2.4.5.dfsg1-0.9 Severity: grave Tags: security patch http://www.overflow.pl/adv/imsgiheap.txt reported a buffer overflow in the SGI parser (demo exploit linked in the report). This has been assigned CVE-2006-4144, please mention this number in the changelog when yo