Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 3.0: DSA 549-1 Critical: Remote Code Execution in gtk+2.0

debian
Calendar Grey September 16, 2004
Debian Logo
Upgrade gtk+2.0 on your Debian system to enhance security against remote code execution vulnerabilities in gdk-pixbuf.
Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuflibrary used in Gtk.

Summary

Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuf
library used in Gtk. It is possible for an attacker to execute
arbitrary code on the victims machine. Gdk-pixbuf for Gtk+1.2 is an
external package. For Gtk+2.0 it's part of the main gtk package.

The Common Vulnerabilities and Exposures Project identifies the
following vulnerabilities:

CAN-2004-0782

Heap-based overflow in pixbuf_create_from_xpm.

CAN-2004-0783

Stack-based overflow in xpm_extract_color.

CAN-2004-0788

Integer overflow in the ico loader.

For the stable distribution (woody) these problems have been fixed in
version 2.0.2-5woody2.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your Gtk packages.


Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will upda...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: gtk+2.0
CVE ID: CAN-2004-0782 CAN-2004-0783 CAN-2004-0788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here