Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu: 789-2 High: ImageMagick Buffer Overflow Vulnerability

debian
Calendar Grey September 16, 2004
Debian Logo
Several vulnerabilities detected in gdk-pixbuf could lead to unauthorized code execution; it is advised to apply updates promptly.
Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuflibrary used in Gtk.

Summary

Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuf
library used in Gtk. It is possible for an attacker to execute
arbitrary code on the victims machine. Gdk-pixbuf for Gtk+1.2 is an
external package. For Gtk+2.0 it's part of the main gtk package.

The Common Vulnerabilities and Exposures Project identifies the
following vulnerabilities:

CAN-2004-0753

Denial of service in bmp loader.

CAN-2004-0782

Heap-based overflow in pixbuf_create_from_xpm.

CAN-2004-0788

Integer overflow in the ico loader.

For the stable distribution (woody) these problems have been fixed in
version 0.17.0-2woody2.

For the unstable distribution (sid) these problems have been fixed in
version 0.22.0-7.

We recommend that you upgrade your gdk-pixbuf packages.


Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: gdk-pixbuf
CVE ID: CAN-2004-0753 CAN-2004-0782 CAN-2004-0788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here