Skip to content
Commit 266afc6c authored by Hugo Lefeuvre's avatar Hugo Lefeuvre
Browse files

tiff: CVE-2018-5360 same as CVE-2014-8127

CVE-2018-5360 same issue as bug #2500 (SamplesPerPixel changed without
updating SMinSampleValue).

Build a pre-739dcd28 libTIFF with asan and

$ tiffset graphicsmagic_0.tif

and you will get the exact same crash.

undetermined not removed yet since I still have to check again the
fixed Debian version (first official release to ship patch is 4.0.7
but the fix might have been introduced in earlier Debian releases)

see https://sourceforge.net/p/graphicsmagick/bugs/540/ (post awaiting
moderation at the moment)
parent 155ed502
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment