Possible SVG vulnerability affecting Firefox, evince, eog, Gimp and more

Bug #253804 reported by Till Ulen
254
Affects Status Importance Assigned to Milestone
eog (Ubuntu)
Invalid
Undecided
Unassigned
evince (Ubuntu)
Invalid
Undecided
Unassigned
firefox (Ubuntu)
Invalid
Undecided
Unassigned
firefox-3.0 (Ubuntu)
Invalid
Undecided
Unassigned
gimp (Ubuntu)
Invalid
Undecided
Kees Cook

Bug Description

There's an alleged proof-of-concept exploit published on July 8, 2008 at http://www.milw0rm.com/exploits/6029 that says:

"Malicious SVG file DoS

The following applications were tested in their latest revisions:
Firefox's "browse for file, preview" object on linux: affected
evince on linux: affected
eog on linux: affected
gimp on linux: affected
inkscape on linux: unaffected
Microsoft Visio on windows: unaffected

It is unknown at this time whether code execution is possible..."

Unfortunately I currently lack the resources to verify the existence of the vulnerability.

WARNING: the .zip file might harm your computer. Don't open it on your normal machine.

A more or less safe way to test it would be to physically disconnect any important devices (all hard disks, network connections to any networks that trust your machine, etc.) and to boot from a live CD. But you should still know what you're doing.

Revision history for this message
Kees Cook (kees) wrote :

I cannot reproduce this on any of the linked packages. Have you seen actual crashes?

Changed in gimp:
status: New → Invalid
Changed in firefox:
status: New → Invalid
Changed in firefox-3.0:
status: New → Invalid
Changed in evince:
status: New → Invalid
Changed in eog:
status: New → Invalid
Changed in gimp:
assignee: nobody → kees
Revision history for this message
Till Ulen (tillulen) wrote : Re: [Bug 253804] Re: Possible SVG vulnerability affecting Firefox, evince, eog, Gimp and more

On Fri, Aug 1, 2008 at 05:01, Kees Cook wrote:
> I cannot reproduce this on any of the linked packages. Have you seen
> actual crashes?

No, I didn't test it at all because I've got only one machine and it's
in production use right now. I will post an update if I can reproduce
it. I've also posted the link to oss-security in case anybody is
interested to check whether it is a fake or not.

Till Ulen (tillulen)
description: updated
Till Ulen (tillulen)
description: updated
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.