Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 16.04 LTS: USN-3075-1 Critical: Imlib2 DoS Threat

ubuntu
Calendar Grey September 9, 2016
Scroller Ubuntu
Multiple Imlib2 security flaws addressed in Ubuntu advisory USN-3076-1. Mitigate crashes and bolster system integrity.
Several security issues were fixed in Imlib2.

Summary

Several security issues were fixed in Imlib2.

Software Description:

- imlib2: Image manipulation and rendering library

Details:

Jakub Wilk discovered an out of bounds read in the GIF loader

implementation in Imlib2. An attacker could use this to cause a

denial of service (application crash) or possibly obtain sensitive

information. (CVE-2016-3994)

Yuriy M. Kaminskiy discovered an off-by-one error when handling

coordinates in Imlib2. An attacker could use this to cause a denial of

service (application crash). (CVE-2016-3993)

Yuriy M. Kaminskiy discovered that integer overflows existed in Imlib2

when handling images with large dimensions. An attacker could use

this to cause a denial of service (memory exhaustion or application

crash). (CVE-2014-9771, CVE-2016-4024)

Kevin Ryde discovered that the ellipse drawing code in Imlib2 would

attempt to divide by zero when drawing a 2x1 ellipse. An attacker

could use this to cause a denial of service (application crash).

(CVE-2011-5326)

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libimlib2                       1.4.7-1ubuntu0.1

Ubuntu 14.04 LTS:
  libimlib2                       1.4.6-2ubuntu0.1

Ubuntu 12.04 LTS:
  libimlib2                       1.4.4-1ubuntu0.1

After a standard system update you will need to restart applications
that make use of Imlib2 to make all the necessary changes.

References

CVE-2011-5326, CVE-2014-9762, CVE-2014-9763, CVE-2014-9764,

CVE-2014-9771, CVE-2016-3993, CVE-2016-3994, CVE-2016-4024

Severity
critical
Lowest
Low
Medium
High
Critical

September 09, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.