[From nobody Sat Sep 12 09:23:05 2026
Received: (at submit) by bugs.debian.org; 10 Jul 2022 17:19:46 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.2-bugs.debian.org_2005_01_02
 (2018-09-13) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-8.6 required=4.0 tests=BAYES_00,FOURLA,
 RCVD_IN_DNSWL_MED,SPF_HELO_NONE,SPF_NONE,TXREP,T_SCC_BODY_TEXT_LINE
 autolearn=no autolearn_force=no
 version=3.4.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 39; hammy, 150; neutral, 50; spammy,
 0. spammytokens: hammytokens:0.000-+--H*RU:inutil.org,
 0.000-+--H*r:jmm, 0.000-+--UD:security-tracker.debian.org,
 0.000-+--security-tracker.debian.org, 0.000-+--securitytrackerdebianorg
Return-path: &lt;jmm@inutil.org&gt;
Received: from inutil.org ([109.69.64.57]:35342
 helo=viruvalge.hosting.plutex.de)
 by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.92) (envelope-from &lt;jmm@inutil.org&gt;) id 1oAaaw-0006tp-1U
 for submit@bugs.debian.org; Sun, 10 Jul 2022 17:19:46 +0000
Received: by viruvalge.hosting.plutex.de (Postfix, from userid 112)
 id 353C9402EC; Sun, 10 Jul 2022 19:19:44 +0200 (CEST)
Received: from hullmann.fritz.box (p548dce20.dip0.t-ipconnect.de
 [84.141.206.32])
 by viruvalge.hosting.plutex.de (Postfix) with ESMTPSA id 6F6AA40124
 for &lt;submit@bugs.debian.org&gt;; Sun, 10 Jul 2022 19:19:43 +0200 (CEST)
Received: from jmm by hullmann.fritz.box with local (Exim 4.95)
 (envelope-from &lt;jmm@hullmann.westfalen.local&gt;) id 1oAaat-0002va-I7
 for submit@bugs.debian.org; Sun, 10 Jul 2022 19:19:43 +0200
Date: Sun, 10 Jul 2022 19:19:43 +0200
To: submit@bugs.debian.org
Subject: gegl: CVE-2018-10111 CVE-2018-10112
Message-ID: &lt;YssKL33VrDKt0Alj@pisco.westfalen.local&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
From: =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= &lt;jmm@inutil.org&gt;
Delivered-To: submit@bugs.debian.org

Source: gegl
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerabilities were published for gegl.

CVE-2018-10111[0]:
| An issue was discovered in GEGL through 0.3.32. The render_rectangle
| function in process/gegl-processor.c has unbounded memory allocation,
| leading to a denial of service (application crash) upon allocation
| failure.

https://bugzilla.gnome.org/show_bug.cgi?id=795249
https://gitlab.gnome.org/GNOME/gegl/issues/65
POC https://github.com/xiaoqx/pocs/tree/master/gegl#2-gegl-dos-1

CVE-2018-10112[1]:
| An issue was discovered in GEGL through 0.3.32. The
| gegl_tile_backend_swap_constructed function in buffer/gegl-tile-
| backend-swap.c allows remote attackers to cause a denial of service
| (write access violation) or possibly have unspecified other impact via
| a malformed PNG file that is mishandled during a call to the
| babl_format_get_bytes_per_pixel function in babl-format.c in babl
| 0.1.46.

https://bugzilla.gnome.org/show_bug.cgi?id=795249
https://gitlab.gnome.org/GNOME/gegl/issues/65
https://github.com/xiaoqx/pocs/tree/master/gegl#4-gegl-outbound-write-2

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-10111
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10111
[1] https://security-tracker.debian.org/tracker/CVE-2018-10112
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10112

Please adjust the affected versions in the BTS as needed.
]