Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Ubuntu 15.10: USN-2898-1 Moderate: GTK+ Crash Threat Report

ubuntu
Calendar Grey February 15, 2016
Scroller Ubuntu
A vulnerability in GTK+ permits remote adversaries to disrupt applications or carry out unauthorized commands on compromised Ubuntu machines.
GTK+ could be made to crash or run programs as your login if it processed a specially crafted image.

Summary

GTK+ could be made to crash or run programs as your login if it processed a

specially crafted image.

Software Description:

- gtk+2.0: GTK+ graphical user interface library

- gtk+3.0: GTK+ graphical user interface library

Details:

It was discovered that GTK+ incorrectly handled certain large images. A

remote attacker could use this issue to cause GTK+ applications to crash,

resulting in a denial of service, or possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libgtk2.0-0                     2.24.28-1ubuntu1.1

Ubuntu 14.04 LTS:
  libgtk2.0-0                     2.24.23-0ubuntu1.4

Ubuntu 12.04 LTS:
  libgtk-3-0                      3.4.2-0ubuntu0.9
  libgtk2.0-0                     2.24.10-0ubuntu6.3

After a standard system update you need to restart your session to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2898-1

CVE-2013-7447

February 15, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.