Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian Jessie: DSA-3555-1 Moderate: Imlib2 Memory Issues

debian
Calendar Grey April 23, 2016
Debian Logo
This notice outlines various vulnerabilities found in imlib2 impacting Debian environments, along with suggested corrective measures.
Several vulnerabilities were discovered in imlib2, an image manipulation library

Summary

CVE-2011-5326

Kevin Ryde discovered that attempting to draw a 2x1 radi ellipse
results in a floating point exception.

CVE-2014-9771

It was discovered that an integer overflow could lead to invalid
memory reads and unreasonably large memory allocations.

CVE-2016-3993

Yuriy M. Kaminskiy discovered that drawing using coordinates from
an untrusted source could lead to an out-of-bound memory read, which
in turn could result in an application crash.

CVE-2016-3994

Jakub Wilk discovered that a malformed image could lead to an
out-of-bound read in the GIF loader, which may result in an
application crash or information leak.

CVE-2016-4024

Yuriy M. Kaminskiy discovered an integer overflow that could lead to
an insufficient heap allocation and out-of-bound memory write.

For the oldstable distribution (wheezy), these problems have been fixed
in version 1.4.5-1+deb7u2.

For the stable distribution (jessie), these problems have been fixed in
version 1.4.6-2+deb8u2.

For th...

Read the Full Advisory

Package: imlib2
CVE ID: CVE-2011-5326 CVE-2014-9771 CVE-2016-3993 CVE-2016-3994

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here