mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-10-01 23:39:36 +00:00
Fix following CVEs for imagemagick: CVE-2021-20311, CVE-2021-20312, CVE-2021-20313 CVE-2021-20309, CVE-2021-20310, CVE-2021-3610 CVE-2022-0284, CVE-2022-2719 fix-cipher-leak.patch fixes CVE-2021-20311, CVE-2021-20312, CVE-2021-20313 Ignore following CVES as current version is not affected by them: CVE-2014-9826, CVE-2016-7538, CVE-2017-5506 Signed-off-by: Sana Kazi <sanakazi720@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
137 lines
4.5 KiB
Diff
137 lines
4.5 KiB
Diff
From 716496e6df0add89e9679d6da9c0afca814cfe49 Mon Sep 17 00:00:00 2001
|
|
From: Cristy <urban-warrior@imagemagick.org>
|
|
Date: Sun, 3 Apr 2022 14:35:29 -0400
|
|
Subject: [PATCH] do not attempt to write a null image list (thanks to Vinay
|
|
Rohila)
|
|
|
|
CVE: CVE-2022-2719
|
|
Upstream-Status: Backport [https://github.com/ImageMagick/ImageMagick/commit/716496e6df0add89e9679d6da9c0afca814cfe49.patch]
|
|
Signed-off-by: Sana Kazi Sana.Kazi@kpit.com
|
|
---
|
|
MagickWand/operation.c | 3 ++-
|
|
coders/tim2.c | 30 ++++++++++++++----------------
|
|
2 files changed, 16 insertions(+), 17 deletions(-)
|
|
|
|
diff --git a/MagickWand/operation.c b/MagickWand/operation.c
|
|
index 383dc7c8098..95596035367 100644
|
|
--- a/MagickWand/operation.c
|
|
+++ b/MagickWand/operation.c
|
|
@@ -4893,7 +4893,8 @@ WandPrivate void CLINoImageOperator(Magi
|
|
if (IfPlusOp)
|
|
write_images=CloneImageList(_images,_exception);
|
|
write_info=CloneImageInfo(_image_info);
|
|
- (void) WriteImages(write_info,write_images,arg1,_exception);
|
|
+ if (write_images != (Image *) NULL)
|
|
+ (void) WriteImages(write_info,write_images,arg1,_exception);
|
|
write_info=DestroyImageInfo(write_info);
|
|
if (IfPlusOp)
|
|
write_images=DestroyImageList(write_images);
|
|
diff --git a/coders/tim2.c b/coders/tim2.c
|
|
index e55170d8205..110542e45ba 100644
|
|
--- a/coders/tim2.c
|
|
+++ b/coders/tim2.c
|
|
@@ -60,8 +60,7 @@
|
|
#include "MagickCore/static.h"
|
|
#include "MagickCore/string_.h"
|
|
#include "MagickCore/module.h"
|
|
-
|
|
-
|
|
+
|
|
/*
|
|
Typedef declarations
|
|
*/
|
|
@@ -123,8 +122,7 @@ typedef enum
|
|
RGB24=1,
|
|
RGBA16=2,
|
|
} TIM2ColorEncoding;
|
|
-
|
|
-
|
|
+
|
|
/*
|
|
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
|
% %
|
|
@@ -142,7 +140,8 @@ typedef enum
|
|
%
|
|
% The format of the ReadTIM2Image method is:
|
|
%
|
|
-% Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception)
|
|
+% Image *ReadTIM2Image(const ImageInfo *image_info,
|
|
+% ExceptionInfo *exception)
|
|
%
|
|
% A description of each parameter follows:
|
|
%
|
|
@@ -600,13 +599,13 @@ static MagickBooleanType ReadTIM2ImageData(const ImageInfo *image_info,
|
|
image_info->filename);
|
|
break;
|
|
}
|
|
- if (csm==CSM1)
|
|
+ if (csm == CSM1)
|
|
{
|
|
PixelInfo
|
|
*oldColormap;
|
|
|
|
- oldColormap=(PixelInfo *) AcquireQuantumMemory((size_t)(image->colors)+1,
|
|
- sizeof(*image->colormap));
|
|
+ oldColormap=(PixelInfo *) AcquireQuantumMemory((size_t)(image->colors)+
|
|
+ 1,sizeof(*image->colormap));
|
|
if (oldColormap == (PixelInfo *) NULL)
|
|
ThrowBinaryException(ResourceLimitError,"MemoryAllocationFailed",
|
|
image_info->filename);
|
|
@@ -617,7 +616,8 @@ static MagickBooleanType ReadTIM2ImageData(const ImageInfo *image_info,
|
|
return(status);
|
|
}
|
|
|
|
-static Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception)
|
|
+static Image *ReadTIM2Image(const ImageInfo *image_info,
|
|
+ ExceptionInfo *exception)
|
|
{
|
|
Image
|
|
*image;
|
|
@@ -626,6 +626,7 @@ static Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception
|
|
status;
|
|
|
|
ssize_t
|
|
+ i,
|
|
str_read;
|
|
|
|
TIM2FileHeader
|
|
@@ -685,7 +686,7 @@ static Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception
|
|
*/
|
|
if (file_header.image_count != 1)
|
|
ThrowReaderException(CoderError,"NumberOfImagesIsNotSupported");
|
|
- for (int i=0; i < file_header.image_count; ++i)
|
|
+ for (i=0; i < (ssize_t) file_header.image_count; i++)
|
|
{
|
|
char
|
|
clut_depth,
|
|
@@ -780,8 +781,7 @@ static Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception
|
|
break;
|
|
}
|
|
image=SyncNextImageInList(image);
|
|
- status=SetImageProgress(image,LoadImagesTag,image->scene-1,
|
|
- image->scene);
|
|
+ status=SetImageProgress(image,LoadImagesTag,image->scene-1,image->scene);
|
|
if (status == MagickFalse)
|
|
break;
|
|
}
|
|
@@ -790,8 +790,7 @@ static Image *ReadTIM2Image(const ImageInfo *image_info,ExceptionInfo *exception
|
|
return(DestroyImageList(image));
|
|
return(GetFirstImageInList(image));
|
|
}
|
|
-
|
|
-
|
|
+
|
|
/*
|
|
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
|
% %
|
|
@@ -825,8 +824,7 @@ ModuleExport size_t RegisterTIM2Image(void)
|
|
(void) RegisterMagickInfo(entry);
|
|
return(MagickImageCoderSignature);
|
|
}
|
|
-
|
|
-
|
|
+
|
|
/*
|
|
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
|
|
% %
|