Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora Core 2: FEDORA-2004-287 Critical: gdk-pixbuf Image Threats

fedora
Calendar Grey September 15, 2004
Dist Fedora Esm H88
Critical vulnerabilities in gdk-pixbuf identified within the Fedora Core 2 upgrade require immediate measures to safeguard the security of the system.
Several vulnerabilities.

Summary

The gdk-pixbuf package contains an image loading library used with the

GNOME GUI desktop environment. The GdkPixBuf library provides image

loading facilities, the rendering of a GdkPixBuf into various formats

(drawables or GdkRGB buffers), and a cache interface.

Update Information:

During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was discovered in the BMP image processor of gdk-pixbuf. An attacker could create a carefully crafted BMP file which would cause an application to enter an infinite loop and not respond to user input when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0753 to this issue.

During a security audit, Chris Evans discovered a stack and a heap overflow in the XPM image decoder. An attacker could create a carefully crafted XPM file which could cause an application linked with gtk2 to crash or possibly execute arbitrary code when the file was opened by a victim. (CAN-2004-0782, CAN-2004-0783)

Chris Evans also discovered an integer overflow in the ICO image decoder. An attacker could create a carefully crafted ICO file which could cause an application linked with gtk2 to crash when the file is opened by a victim. (CAN-2004-0788)

...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-287 2004-09-15
Product : Fedora Core 2 Name : gdk-pixbuf Version : 0.22.0 Release : 11.2.3 Summary : An image loading library used with GNOME. Description : The gdk-pixbuf package contains an image loading library used with the GNOME GUI desktop environment. The GdkPixBuf library provides image loading facilities, the rendering of a GdkPixBuf into various formats (drawables or GdkRGB buffers), and a cache interface.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: gdk-pixbuf
Version: 0.22.0
Release: 11.2.3
Summary: An image loading library used with GNOME.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here