New issue
Advanced search Search tips

Issue 760914 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in media-libs/tiff

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Aug 31 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: media-libs/tiff
Package Version: [cpe:/a:libtiff:libtiff:4.0.6 cpe:/a:libtiff:libtiff:4.0.8 cpe:/a:libtiff_project:libtiff:4.0.6 cpe:/a:libtiff_project:libtiff:4.0.8]

Advisory: CVE-2017-13726
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-13726
  CVSS severity score: 4.3/10.0
  Confidence: high
  Description:

There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
Advisory: CVE-2017-13727
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-13727
  CVSS severity score: 4.3/10.0
  Confidence: high
  Description:

There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.


 

Comment 1 by est...@chromium.org, Aug 31 2017

Owner: jorgelo@chromium.org
Status: Assigned (was: Untriaged)
Jorge, can you take a look please? Thanks!
Labels: -ComponentOSKernel Security_Severity-Low
Denial of service is Low. There's no libtiff release with the patches, so we might need to cherry-pick them.
Components: OS>Systems
TIFF is used by the scanning subsystem so OS>Systems.
Cc: vapier@chromium.org
Components: Internals>Plugins>PDF
Labels: Security_Impact-Stable
PDFium also uses libtiff -- does it use the same version? Looks like it's also at 4.0.8. vapier, please take a look, and we can file a separate bug if appropriate.
Cc: npm@chromium.org
+npm who has been taking care of PDFium's libtiff, which is XFA only and not shipped to users currently. We may want to file a separate bug for PDFium's libtiff use and block bug 62400 with that.
Labels: M-65
Status: Started (was: Assigned)
https://chromium-review.googlesource.com/#/c/chromiumos/overlays/portage-stable/+/834908 fixes CrOS.
Project Member

Comment 7 by bugdroid1@chromium.org, Dec 20 2017

Status: Fixed (was: Started)
Project Member

Comment 9 by sheriffbot@chromium.org, Dec 21 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 10 by sheriffbot@chromium.org, Mar 29 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment