This update includes a fix for a denial-of-service issue (CVE-2007-3568) whereby an attacker who could get an imlib-using user to view a specially-crafted BMP image could cause the user's CPU to go into an infinite loop.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2007-4594 2007-12-28 16:42:30 --------------------------------------------------------------------------------Name : imlib Product : Fedora 8 Version : 1.9.15 Release : 6.fc8 URL : [] Summary : An image loading and rendering library for X11R6 Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. The imlib package also contains the imlib_config program, which you can use to configure the Imlib image loading and rendering library. Imlib_config can be used to control how Imlib uses color and handles gamma corrections, etc. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. --------------------------------------------------------------------------------Update Information: This update includes a fix for a denial-of-service issue (CVE-2007-3568) whereby an attacker who could get an imlib-using user to view a specially-crafted BMP image could cause the user's CPU to go into an infinite loop. --------------------------------------------------------------------------------ChangeLog: * Tue Dec 18 2007 Paul Howarth 1:1.9.15-6 - include patch to fix a DoS caused via a BMP image with a Bits Per Page (BPP) value of 0 (#426091, CVE-2007-3568); thanks to Peter Volkov at Gentoo for the heads-up - remove URL tag; this legacy package has no active upstream source, and documentation for it is gradually disappearing from theInternet * Wed Nov 28 2007 Adam Jackson 1:1.9.15-5 - imlib-1.9.15-check-for-shm-pixmaps.patch: MIT-SHM pixmaps are optional, so check that they exist before using them. (#357241) --------------------------------------------------------------------------------References: [ 1 ] Bug #426091 - CVE-2007-3568 imlib: infinite loop DoS using crafted BMP image https://bugzilla.redhat.com/show_bug.cgi?id=426091 --------------------------------------------------------------------------------Updated packages: 81993c0d805b221493bb24036ccae8e5209687d5 imlib-debuginfo-1.9.15-6.fc8.ppc64.rpm e6d681cc1af89dce736be2876040805748aaefda imlib-devel-1.9.15-6.fc8.ppc64.rpm 55f4e7dc59b4ad327858af5741ed7a1ea7dbea84 imlib-1.9.15-6.fc8.ppc64.rpm 651d6e6b8639cfdee47a318538755694e0394275 imlib-debuginfo-1.9.15-6.fc8.i386.rpm 45a2b25a98ea786b0a9c2ae1007f132f74f7a7c2 imlib-devel-1.9.15-6.fc8.i386.rpm 41ed0ab7479a458b6e1d3b3e3b67d35310b3617d imlib-1.9.15-6.fc8.i386.rpm d2251b17c23b1e21b00cd588da143356fddc95ab imlib-debuginfo-1.9.15-6.fc8.x86_64.rpm 22a12a4158488a7e196ebe6d84bee127e35ea5aa imlib-devel-1.9.15-6.fc8.x86_64.rpm 592a590e859912f9bada71b62c744d8177f5d75d imlib-1.9.15-6.fc8.x86_64.rpm bedeec73d1bc9647bb592226cc23d21af1935f6a imlib-debuginfo-1.9.15-6.fc8.ppc.rpm 811539b74ad106b4161b54ebe4831ac6b66d2778 imlib-devel-1.9.15-6.fc8.ppc.rpm 6918dd5ca716ec05e8ce468cd11ce0feae3d39b0 imlib-1.9.15-6.fc8.ppc.rpm a8f1978f1762fb9de957afc612b8f58df9f198f6 imlib-1.9.15-6.fc8.src.rpm This update can be installed with the "yum" update program. Use su -c 'yum update imlib' at the command line. For more information, refer to "Managing Software with yum", available at . --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Upgrade package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 548-2
Pavel Kankovsky discovered that several overflows found in the libXpm library were also present in imlib, an imaging library for X and X11. An attacker could create a carefully crafted image file in such a way that it could cause an application linked with imlib to execute arbitrary code when the file was opened by a victim.. --------------------------------------------------------------------------Debian Security Advisory DSA 618-1
Marcus Meissner discovered a heap overflow error in imlib, an imaginglibrary for X and X11, that could be abused by an attacker to executearbitrary code on the vicims machine.. -------------------------------------------------------------------------- Debian Security Advisory DSA 548-1
An updated imlib package that fixes several heap overflows is now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated imlib package fixes security vulnerability Advisory ID: RHSA-2004:465-01 Issue date: 2004-09-15 Updated on: 2004-09-15 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0817 --------------------------------------------------------------------- 1. Summary: An updated imlib package that fixes several heap overflows is now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: Imlib is an image loading and rendering library. Several heap overflow flaws were found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it could cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the SystemAdministration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 130909 - CAN-2004-0817 heap overflow in BMP decoder 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm ia64: ca8f753c817cbe0bf24ac0ac2b03bccc imlib-1.9.13-4.2.ia64.rpm 11060c4560ee42e3e9e0e482a88189c2 imlib-cfgeditor-1.9.13-4.2.ia64.rpm 11e6bd0ee4caca73cbc0ddc80bf1d793 imlib-devel-1.9.13-4.2.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm ia64: ca8f753c817cbe0bf24ac0ac2b03bccc imlib-1.9.13-4.2.ia64.rpm 11060c4560ee42e3e9e0e482a88189c2 imlib-cfgeditor-1.9.13-4.2.ia64.rpm 11e6bd0ee4caca73cbc0ddc80bf1d793 imlib-devel-1.9.13-4.2.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm ppc: 3d5eae85598168b6e337a0689eb2d743 imlib-1.9.13-13.3.ppc.rpm c9bd4375d8e077fcc70a638804d16b65 imlib-devel-1.9.13-13.3.ppc.rpm s390: 17404e9fdddd26a89d81df23e3aae7db imlib-1.9.13-13.3.s390.rpm 5a3c49f094187deb72b9c522fedd5724 imlib-devel-1.9.13-13.3.s390.rpm s390x: 81d3bbb3472454bd14c748c60c219d2b imlib-1.9.13-13.3.s390x.rpm 7e6739f7b72993dadbc4a489898c83c1 imlib-devel-1.9.13-13.3.s390x.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Desktop version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: Bug 151034 – buffer overflow in bmp handling CVE -CVE-2004-0817 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . The updated imlib framework tackles significant buffer overflow issues within Red Hat environments, enhancing the overall protective strategies.. Red Hat Enterprise Linux, imlib heap overflow, critical update. . Severity: Critical. LinuxSecurity.com Team
Several heap overflow vulnerabilities have been found in the imlib BMPimage handler. An attacker could create a carefully crafted BMP file insuch a way that it would cause an application linked with imlib toexecute arbitrary code when the file was opened by a victim.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-300 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : imlib Version : 1.9.13 Release : 15.fc1 Summary : An image loading and rendering library for X11R6. Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. You may also want to install the imlib-cfgeditor package, which will help you configure Imlib. --------------------------------------------------------------------- Update Information: Several heap overflow vulnerabilities have been found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to these issues. --------------------------------------------------------------------- * Thu Sep 09 2004 Matthias Clasen - Security fixes --------------------------------------------------------------------- This update can be downloaded from: ... 03a77921e2efd86e0703d66de59cad1c SRPMS/imlib-1.9.13-15.fc1.src.rpm 7c819092b3f54e6fba51460f10d4d2db x86_64/imlib-1.9.13-15.fc1.x86_64.rpm 296479ab2f3ebfdb1b43c4454d881009 x86_64/imlib-devel-1.9.13-15.fc1.x86_64.rpm 5b66680b22684df822ef4f38d6e87a35 x86_64/imlib-cfgeditor-1.9.13-15.fc1.x86_64.rpm f211ba31e2b13a872d0c318b4892c624 x86_64/debug/imlib-debuginfo-1.9.13-15.fc1.x86_64.rpm 8bd4bb9bbcad02a8442edd5bd6afd8f2 i386/imlib-1.9.13-15.fc1.i386.rpm 469d4ed01e2ba0b49fdcd0fa01323052 i386/imlib-devel-1.9.13-15.fc1.i386.rpm fa26f3f2c7a877c806b675fc8de68203 i386/imlib-cfgeditor-1.9.13-15.fc1.i386.rpm 7d0d786eb8e5ea9793c2505267a2f650 i386/debug/imlib-debuginfo-1.9.13-15.fc1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Reevaluate the memory management strategies in the BMP processing module of imlib to mitigate buffer overflow risks and safeguard Fedora users from exploitation threats. Fedora Security Update, Imlib Patch, BMP Image Handler Fix, Core 1 Security. . LinuxSecurity.com Team
Several heap overflow vulnerabilities have been found in the imlib BMPimage handler.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-300 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : imlib Version : 1.9.13 Release : 15.fc1 Summary : An image loading and rendering library for X11R6. Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. You may also want to install the imlib-cfgeditor package, which will help you configure Imlib. --------------------------------------------------------------------- Update Information: Several heap overflow vulnerabilities have been found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to these issues. --------------------------------------------------------------------- * Thu Sep 09 2004 Matthias Clasen - Security fixes --------------------------------------------------------------------- This update can be downloaded from: 03a77921e2efd86e0703d66de59cad1c SRPMS/imlib-1.9.13-15.fc1.src.rpm 7c819092b3f54e6fba51460f10d4d2db x86_64/imlib-1.9.13-15.fc1.x86_64.rpm 296479ab2f3ebfdb1b43c4454d881009 x86_64/imlib-devel-1.9.13-15.fc1.x86_64.rpm 5b66680b22684df822ef4f38d6e87a35 x86_64/imlib-cfgeditor-1.9.13-15.fc1.x86_64.rpm f211ba31e2b13a872d0c318b4892c624 x86_64/debug/imlib-debuginfo-1.9.13-15.fc1.x86_64.rpm 8bd4bb9bbcad02a8442edd5bd6afd8f2 i386/imlib-1.9.13-15.fc1.i386.rpm 469d4ed01e2ba0b49fdcd0fa01323052 i386/imlib-devel-1.9.13-15.fc1.i386.rpm fa26f3f2c7a877c806b675fc8de68203 i386/imlib-cfgeditor-1.9.13-15.fc1.i386.rpm 7d0d786eb8e5ea9793c2505267a2f650 i386/debug/imlib-debuginfo-1.9.13-15.fc1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Multiple buffer overflow vulnerabilities in imlib may lead to arbitrary code execution. Upgrade Fedora for safety.. Imlib Security Update, Heap Overflow, Fedora Core Issues. . Severity: Critical. LinuxSecurity.com Team
ImageMagick, imlib and imlib2 contain exploitable buffer overflow vulnerabilities in the BMP image processing code.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ImageMagick, imlib, imlib2: BMP decoding buffer overflows Date: September 08, 2004 Bugs: #62309, #62487 ID: 200409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= ImageMagick, imlib and imlib2 contain exploitable buffer overflow vulnerabilities in the BMP image processing code. Background ========= ImageMagick is a suite of image manipulation utilities and libraries used for a wide variety of image formats. imlib is a general image loading and rendering library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/imagemagick < 6.0.7.1 > = 6.0.7.1 2 media-libs/imlib < 1.9.14-r2 > = 1.9.14-r2 3 media-libs/imlib2 < 1.1.2 > = 1.1.2 ------------------------------------------------------------------- 3 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Due to improper bounds checking, ImageMagick and imlib are vulnerable to a buffer overflow when decoding runlength-encoded bitmaps. This bug can be exploited using a specially-crafted BMP image and could potentially allow remote code executionwhen this image is decoded by the user. Impact ===== A specially-crafted runlength-encoded BMP could lead ImageMagick and imlib to crash or potentially execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All ImageMagick users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-gfx/imagemagick-6.0.7.1" # emerge "> =media-gfx/imagemagick-6.0.7.1" All imlib users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-libs/imlib-1.9.14-r2" # emerge "> =media-libs/imlib-1.9.14-r2" All imlib2 users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-libs/imlib2-1.1.2" # emerge "> =media-libs/imlib2-1.1.2" References ========= [ 1 ] CAN-2004-0817 https://www.cve.org/CVERecord?id=CAN-2004-0817 [ 2 ] CAN-2004-0802 https://www.cve.org/CVERecord?id=CAN-2004-0802 [ 3 ] ImageMagick Mailing List [ 4 ] SecurityTracker #1011104 [ 5 ] SecurityTracker #1011105 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200409-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.