After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 749674 - CVE-2015-2785: byzanz: Out-of heap-based buffer write in GIF encoder
CVE-2015-2785: byzanz: Out-of heap-based buffer write in GIF encoder
Status: RESOLVED WONTFIX
Product: byzanz
Classification: Other
Component: general
git master
Other Linux
: Normal major
: ---
Assigned To: byzanz-maint
byzanz-maint
gnome[unmaintained]
Depends on:
Blocks:
 
 
Reported: 2015-05-21 11:00 UTC by Markus Koschany
Modified: 2018-07-01 08:25 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Markus Koschany 2015-05-21 11:00:20 UTC
A security vulnerability was discovered in byzanz' GIF encoder. This is CVE-2015-2785.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2785

The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary code via a crafted Byzanz debug data recording (ByzanzRecording file) to the byzanz-playback command. 


This bug was initially reported to Red Hat's bug tracker:

https://bugzilla.redhat.com/show_bug.cgi?id=852481

You can also find another bug report for Debian at

https://bugs.debian.org/778261


A test case / reproducer exists for this vulnerability. Interested parties and developers should contact Red Hat's security team via e-email and ask for it.

secalert@redhat.com
Comment 1 André Klapper 2018-07-01 08:25:11 UTC
Byzanz is not under active development anymore and has not seen code changes for more than five years.
Its codebase has been archived: https://gitlab.gnome.org/Archive/byzanz/commits/master

Closing this report as WONTFIX as part of Bugzilla Housekeeping to reflect reality. Please feel free to reopen this ticket (or rather transfer the project to GNOME Gitlab, as GNOME Bugzilla is deprecated) if anyone takes the responsibility for active development again.