Important: gtk2 security update. Date: Wed, 16 Nov 2005 15:30:32 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 x86_64 now available Comments: To:
Important: gtk2 security update. Date: Wed, 16 Nov 2005 15:30:00 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 i386 now available Comments: To:
David Costanzo found a bug in the way GTK+ processes BMP images. It is possible that a specially crafted BMP image could cause a denial of service attack in applications linked against GTK+. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to this issue.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-268 2005-03-30 ---------------------------------------------------------------------Product : Fedora Core 3 Name : gtk2 Version : 2.4.14 Release : 3.fc3 Summary : The GIMP ToolKit (GTK+), a library for creating GUIs for X. Description : GTK+ is a multi-platform toolkit for creating graphical user interfaces. Offering a complete set of widgets, GTK+ is suitable for projects ranging from small one-off tools to complete application suites. ---------------------------------------------------------------------Update Information: David Costanzo found a bug in the way GTK+ processes BMP images. It is possible that a specially crafted BMP image could cause a denial of service attack in applications linked against GTK+. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to this issue. ---------------------------------------------------------------------* Mon Mar 28 2005 Matthias Clasen - 2.4.14-3.fc3 - Fix a double free in the bmp loader ---------------------------------------------------------------------This update can be downloaded from: 8c9c1a539e15629f204038597c57e75a SRPMS/gtk2-2.4.14-3.fc3.src.rpm 6491f2ebf95a79a0fafdd90256033189 x86_64/gtk2-2.4.14-3.fc3.x86_64.rpm 7facd80dc1c9ffc2e1745cb1505096c0 x86_64/gtk2-devel-2.4.14-3.fc3.x86_64.rpm 922ad9d8b24a4a580bca1f3461c1fcde x86_64/debug/gtk2-debuginfo-2.4.14-3.fc3.x86_64.rpm 9351093394765c34bc5a6b28e8db301b x86_64/gtk2-2.4.14-3.fc3.i386.rpm 9351093394765c34bc5a6b28e8db301b i386/gtk2-2.4.14-3.fc3.i386.rpm abb369e8b7dbcbe785a23d9cf52ca2a0 i386/gtk2-devel-2.4.14-3.fc3.i386.rpm 816116449734868587e069851dc57a62 i386/debug/gtk2-debuginfo-2.4.14-3.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list
Updates GTK+ to the current stable release 2.4.14. For details about the bugs which have been fixed in this release, see https://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00007.html. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-518 2004-12-06 ---------------------------------------------------------------------Product : Fedora Core 2 Name : gtk2 Version : 2.4.14 Release : 1.fc2 Summary : The GIMP ToolKit (GTK+), a library for creating GUIs for X. Description : GTK+ is a multi-platform toolkit for creating graphical user interfaces. Offering a complete set of widgets, GTK+ is suitable for projects ranging from small one-off tools to complete application suites. ---------------------------------------------------------------------Update Information: Updates GTK+ to the current stable release 2.4.14. For details about the bugs which have been fixed in this release, see https://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00007.html ---------------------------------------------------------------------* Mon Dec 06 2004 Matthias Clasen - 2.4.14-1.fc2 - Update to 2.4.14 ---------------------------------------------------------------------This update can be downloaded from: a4a9602ed2be241f2ae6ecb5e7e6a607 SRPMS/gtk2-2.4.14-1.fc2.src.rpm 7d6f067c6ab32e9947e6359ba3b3aea2 x86_64/gtk2-2.4.14-1.fc2.x86_64.rpm ceda83f54e416e1bf0e75e68b9f616f8 x86_64/gtk2-devel-2.4.14-1.fc2.x86_64.rpm 74ad088539108f39eb0244f6305efcb0 x86_64/debug/gtk2-debuginfo-2.4.14-1.fc2.x86_64.rpm 5dfee75d03217f94a1f483a21a7928e0 x86_64/gtk2-2.4.14-1.fc2.i386.rpm 5dfee75d03217f94a1f483a21a7928e0 i386/gtk2-2.4.14-1.fc2.i386.rpm 821146e6f9d95b0d3e72a68a3f58459f i386/gtk2-devel-2.4.14-1.fc2.i386.rpm d840950be38814ecba5d5b2e26d9b976 i386/debug/gtk2-debuginfo-2.4.14-1.fc2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list
The md5sums of the glib2-2.4.7-1.1 and gtk2-2.4.13-2.1 updates don't match the ones in the announcements I sent out.. The md5sums of the glib2-2.4.7-1.1 and gtk2-2.4.13-2.1 updates don't match the ones in the announcements I sent out. I have verified that the packages on are correct, and here are the correct md5sums. Sorry for the confusion, Matthias 55558c084c77e51cf6e0b59e5d3af520 glib2-2.4.7-1.1.i386.rpm 7b317acd641c9949efebdc1efa5faee4 glib2-debuginfo-2.4.7-1.1.i386.rpm 9bb54171158c7094b5048e1dc97d3579 glib2-devel-2.4.7-1.1.i386.rpm a60f1721578374e4e532b4bb10c110ac glib2-2.4.7-1.1.src.rpm 081914d2a266182af22325c626fdf47d glib2-2.4.7-1.1.x86_64.rpm 2d72664e07bab4370c76c46296677c65 glib2-debuginfo-2.4.7-1.1.x86_64.rpm 3f7a71d9af065612d16f644ff70131b5 glib2-devel-2.4.7-1.1.x86_64.rpm 0dd2a5a13414eba573a3c8dae20be156 gtk2-2.4.13-2.1.i386.rpm 3ad8d087e36b337d6370ef99686140b5 gtk2-debuginfo-2.4.13-2.1.i386.rpm 9749b8969be12503c14637854fa76a9c gtk2-devel-2.4.13-2.1.i386.rpm 0bf989bf521318dda13c47b612e88094 gtk2-2.4.13-2.1.src.rpm 718369eecd1dc8eb2cd5523ffa793267 gtk2-2.4.13-2.1.x86_64.rpm 784870296377146238b433a315f2d800 gtk2-debuginfo-2.4.13-2.1.x86_64.rpm 73ef6ea77533f32e75fc831d408567e7 gtk2-devel-2.4.13-2.1.x86_64.rpm -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.