Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Slackware 14.1: 2015-244-01 Critical: Gdk-Pixbuf2 Heap Overflow

slackware
Calendar Grey September 1, 2015
Scroller Slackware
Recent gdk-pixbuf2 updates for Slackware tackle a critical heap overflow flaw, which could result in unauthorized code execution.
New gdk-pixbuf2 packages are available for Slackware 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/gdk-pixbuf2-2.28.2-i486-2_slack14.1.txz: Rebuilt. Gustavo Grieco discovered a heap overflow in the processing of BMP images which may result in the execution of arbitrary code if a malformed image is opened. For more information, see: https://www.cve.org/CVERecord?id=CVE-2015-4491 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/gdk-pixbuf2-2.23.3-i486-2_slack13.37.txz
Updated package for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/gdk-pixbuf2-2.23.3-x86_64-2_slack13.37.txz
Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/gdk-pixbuf2-2.26.1-i486-3_slack14.0.txz
Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/gdk-pixbuf2-2.26.1-x86_64-3_slack14.0.txz
Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/gdk-pixbuf2-2.28.2-i486-2_slack14.1...

Read the Full Advisory

MD5 Signatures

Slackware 13.37 package: 024660dd36a58ffa0793aeb1396e57c7 gdk-pixbuf2-2.23.3-i486-2_slack13.37.txz
Slackware x86_64 13.37 package: d9db7b242d5e68f6032f80af8359563d gdk-pixbuf2-2.23.3-x86_64-2_slack13.37.txz
Slackware 14.0 package: 63d1deaa9e336c09c23025b4d8f8b545 gdk-pixbuf2-2.26.1-i486-3_slack14.0.txz
Slackware x86_64 14.0 package: c2c2e3211a590b125d9e1e1c61e243ed gdk-pixbuf2-2.26.1-x86_64-3_slack14.0.txz
Slackware 14.1 package: 0e83c834301e53e29bf47a5d6818769d gdk-pixbuf2-2.28.2-i486-2_slack14.1.txz
Slackware x86_64 14.1 package: fcc65f4ec956dcc34f7f378e272e600d gdk-pixbuf2-2.28.2-x86_64-2_slack14.1.txz
Slackware -current package: 41baa15dd4e8a2b9527d7582aa2902d8 l/gdk-pixbuf2-2.31.7-i586-1.txz
Slackware x86_64 -current package: 35b915dd5a87fec81db379e07652e74a l/gdk-pixbuf2-2.31.7-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg gdk-pixbuf2-2.28.2-i486-2_slack14.1.txz