In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp. (CVE-2017-14628). In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array . MGASA-2020-0459 - Updated sam2p package fixes security vulnerabilities Publication date: 17 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0459.html Type: security Affected Mageia releases: 7 CVE: CVE-2017-14628, CVE-2017-14629, CVE-2017-14630, CVE-2017-14631, CVE-2017-14636, CVE-2017-14637, CVE-2017-16663, CVE-2018-7487, CVE-2018-7551, CVE-2018-7553, CVE-2018-7554, CVE-2018-12578, CVE-2018-12601 In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp. (CVE-2017-14628). In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array element. (CVE-2017-14629). In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation. (CVE-2017-14630). In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow. (CVE-2017-14631). Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. However, this also causes memory corruption becaus of an attempted write to the invalid d[0xfffffffe] array element. (CVE-2017-14636). In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address. (CVE-2017-14637). In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.(CVE-2017-16663). There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact. (CVE-2018-7487). There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. (CVE-2018-7551). There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. (CVE-2018-7553). There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. (CVE-2018-7554). There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. (CVE-2018-12578). There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. (CVE-2018-12601). References: - https://bugs.mageia.org/show_bug.cgi?id=27746 - https://lists.debian.org/debian-lts-announce/2017/10/msg00007.html - https://lists.debian.org/debian-lts-announce/2017/11/msg00031.html - https://lists.debian.org/debian-lts-announce/2018/04/msg00004.html - https://lists.debian.org/debian-lts-announce/2018/08/msg00010.html - https://www.cve.org/CVERecord?id=CVE-2017-14628 - https://www.cve.org/CVERecord?id=CVE-2017-14629 - https://www.cve.org/CVERecord?id=CVE-2017-14630 - https://www.cve.org/CVERecord?id=CVE-2017-14631 - https://www.cve.org/CVERecord?id=CVE-2017-14636 - https://www.cve.org/CVERecord?id=CVE-2017-14637 - https://www.cve.org/CVERecord?id=CVE-2017-16663 - https://www.cve.org/CVERecord?id=CVE-2018-7487 - https://www.cve.org/CVERecord?id=CVE-2018-7551 - https://www.cve.org/CVERecord?id=CVE-2018-7553 -https://www.cve.org/CVERecord?id=CVE-2018-7554 - https://www.cve.org/CVERecord?id=CVE-2018-12578 - https://www.cve.org/CVERecord?id=CVE-2018-12601 SRPMS: - 7/core/sam2p-0.49.3-2.1.mga7 . Mageia 2020-0460 addresses multiple vulnerabilities in libXYZ impacting versions until 1.2.3, essential for system integrity.. sam2p security update, buffer overflow mageia, denial of service threats. . Severity: Important. LinuxSecurity.com Team
Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats. . Package : sam2p Version : 0.49.2-3+deb8u3 CVE ID : CVE-2018-12578 CVE-2018-12601 Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats. CVE-2018-12578 A heap-buffer-overflow in bmp_compress1_row. Thanks to Peter Szabo for providing a fix. CVE-2018-12601 A heap-buffer-overflow in function ReadImage, in file input-tga.ci. Thanks to Peter Szabo for providing a fix. For Debian 8 "Jessie", these problems have been fixed in version 0.49.2-3+deb8u3. We recommend that you upgrade your sam2p packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential revisions for sam2p toolkit tackling various security flaws, including potential denial of service risks. Upgrade advised.. sam2p Heap Overflow Denial Service Debian. . Severity: Important. LinuxSecurity.com Team
Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact. . Package : sam2p Version : 0.49.1-1+deb7u3 CVE ID : CVE-2018-7487 CVE-2018-7551 CVE-2018-7552 CVE-2018-7553 CVE-2018-7554 Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact. For Debian 7 "Wheezy", these problems have been fixed in version 0.49.1-1+deb7u3. We recommend that you upgrade your sam2p packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update sam2p to version 0.49.2 to address Denial of Service vulnerabilities stemming from several buffer overflow problems.. sam2p security, buffer overflow fix, denial of service mitigation. . LinuxSecurity.com Team
It was discovered that sam2p, a utility to convert raster images and other image formats, was affected by an integer overflow vulnerability with resultant heap-based buffer overflow in input-bmp.ci because width and height multiplications occur unsafely. This may lead to an . Hash: SHA512 Package : sam2p Version : 0.49.1-1+deb7u2 CVE ID : CVE-2017-16663 It was discovered that sam2p, a utility to convert raster images and other image formats, was affected by an integer overflow vulnerability with resultant heap-based buffer overflow in input-bmp.ci because width and height multiplications occur unsafely. This may lead to an application crash or unspecified other impact when a maliciously crafted file is processed. For Debian 7 "Wheezy", these problems have been fixed in version 0.49.1-1+deb7u2. We recommend that you upgrade your sam2p packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Integer overflow vulnerability in Sam2p can lead to crashes when handling specific input files. It is advised to update your Debian 7 system to resolve this security concern.. Sam2p Security, Debian Upgrade, Integer Overflow Issue, Image Processing. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.