Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 8: 2007-4594 Moderate: Imlib DoS Attack From BMP Image

This update includes a fix for a denial-of-service issue (CVE-2007-3568) whereby an attacker who could get an imlib-using user to view a specially-crafted BMP image could cause the user's CPU to go into an infinite loop.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2007-4594 2007-12-28 16:42:30 --------------------------------------------------------------------------------Name : imlib Product : Fedora 8 Version : 1.9.15 Release : 6.fc8 URL : [] Summary : An image loading and rendering library for X11R6 Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. The imlib package also contains the imlib_config program, which you can use to configure the Imlib image loading and rendering library. Imlib_config can be used to control how Imlib uses color and handles gamma corrections, etc. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. --------------------------------------------------------------------------------Update Information: This update includes a fix for a denial-of-service issue (CVE-2007-3568) whereby an attacker who could get an imlib-using user to view a specially-crafted BMP image could cause the user's CPU to go into an infinite loop. --------------------------------------------------------------------------------ChangeLog: * Tue Dec 18 2007 Paul Howarth 1:1.9.15-6 - include patch to fix a DoS caused via a BMP image with a Bits Per Page (BPP) value of 0 (#426091, CVE-2007-3568); thanks to Peter Volkov at Gentoo for the heads-up - remove URL tag; this legacy package has no active upstream source, and documentation for it is gradually disappearing from theInternet * Wed Nov 28 2007 Adam Jackson 1:1.9.15-5 - imlib-1.9.15-check-for-shm-pixmaps.patch: MIT-SHM pixmaps are optional, so check that they exist before using them. (#357241) --------------------------------------------------------------------------------References: [ 1 ] Bug #426091 - CVE-2007-3568 imlib: infinite loop DoS using crafted BMP image https://bugzilla.redhat.com/show_bug.cgi?id=426091 --------------------------------------------------------------------------------Updated packages: 81993c0d805b221493bb24036ccae8e5209687d5 imlib-debuginfo-1.9.15-6.fc8.ppc64.rpm e6d681cc1af89dce736be2876040805748aaefda imlib-devel-1.9.15-6.fc8.ppc64.rpm 55f4e7dc59b4ad327858af5741ed7a1ea7dbea84 imlib-1.9.15-6.fc8.ppc64.rpm 651d6e6b8639cfdee47a318538755694e0394275 imlib-debuginfo-1.9.15-6.fc8.i386.rpm 45a2b25a98ea786b0a9c2ae1007f132f74f7a7c2 imlib-devel-1.9.15-6.fc8.i386.rpm 41ed0ab7479a458b6e1d3b3e3b67d35310b3617d imlib-1.9.15-6.fc8.i386.rpm d2251b17c23b1e21b00cd588da143356fddc95ab imlib-debuginfo-1.9.15-6.fc8.x86_64.rpm 22a12a4158488a7e196ebe6d84bee127e35ea5aa imlib-devel-1.9.15-6.fc8.x86_64.rpm 592a590e859912f9bada71b62c744d8177f5d75d imlib-1.9.15-6.fc8.x86_64.rpm bedeec73d1bc9647bb592226cc23d21af1935f6a imlib-debuginfo-1.9.15-6.fc8.ppc.rpm 811539b74ad106b4161b54ebe4831ac6b66d2778 imlib-devel-1.9.15-6.fc8.ppc.rpm 6918dd5ca716ec05e8ce468cd11ce0feae3d39b0 imlib-1.9.15-6.fc8.ppc.rpm a8f1978f1762fb9de957afc612b8f58df9f198f6 imlib-1.9.15-6.fc8.src.rpm This update can be installed with the "yum" update program. Use su -c 'yum update imlib' at the command line. For more information, refer to "Managing Software with yum", available at . --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . An update addressing a DoS vulnerability inimlib for Fedora 8 resolves potential CPU cycles caused by malicious BMP files. Ensure you apply the update promptly.. imlib DoS fix,Fedora update,image handling issue,cpu infinite loop. . LinuxSecurity.com Team

Calendar 2 Dec 28, 2007 Fedora
87

Debian 3.0 DSA 548-2 Critical: Imlib Remote Code Execution Fix

Upgrade package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 548-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze October 26th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : imlib Vulnerability : unsanitised input Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0817 Marcus Meissner discovered a heap overflow error in imlib, an imaging library for X and X11, that could be abused by an attacker to execute arbitrary code on the victims machine. The updated packages we have provided in DSA 548-1 did not seem to be sufficient, which should be fixed by this update. For the oldstable distribution (woody) this problem has been fixed in version 1.9.14-2woody3. For the stable distribution (sarge) this problem has been fixed in version 1.9.14-16.2. For the unstable distribution (sid) this problem has been fixed in version 1.9.14-17 of imlib and in version 1.9.14-16.2 of imlib+png2. We recommend that you upgrade your imlib1 packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 805 49cd4c7a41987d9962070033239443d8 Size/MD5 checksum: 277866 7ceed888b7bf492eda4a65a8c8b83fc5 Size/MD5 checksum: 748591 1fa54011e4e1db532d7eadae3ced6a8c Architecture independentcomponents: Size/MD5 checksum: 114746 4b2a3a27987b727c580c7915f55fac98 Alpha architecture: Size/MD5 checksum: 119864 39b947b1b9da7b5d3c4a0c3685497647 Size/MD5 checksum: 97312 cdaed511193f56140bc7db055e2f30ea Size/MD5 checksum: 117512 e0d06856fcae92a9097e62d91facf29a Size/MD5 checksum: 262252 2363831432f51438bae06d27f00c99f4 Size/MD5 checksum: 97354 1db8346d4e1a882a5dbbfb94111c29dc ARM architecture: Size/MD5 checksum: 94286 e3eb7882123cce03110297d550830542 Size/MD5 checksum: 75492 8fa464b1ab3cc14cfec566d0b1b30ca7 Size/MD5 checksum: 94248 711e1c742f5dd7eb3e35c8f4f0037236 Size/MD5 checksum: 258312 edd59410ac22b16e31374a41ffc6a220 Size/MD5 checksum: 76372 0fda1783dc22230607fda1ab9eec97f9 Intel IA-32 architecture: Size/MD5 checksum: 78074 d31f28c0eb82c39d45d6484332a26259 Size/MD5 checksum: 69526 c13e60dd0c443e43820c1590bf1d28fe Size/MD5 checksum: 76654 5ed19869a88d463f24ac70504daec8f6 Size/MD5 checksum: 258400 da19f027923ddf6a0b41bcf73eb46eff Size/MD5 checksum: 70002 fd1c31e2db117fbc339410e00f152df4 Intel IA-64 architecture: Size/MD5 checksum: 129242 62ed6b0e7c1a5826208111140680b49a Size/MD5 checksum: 116286 907bcc0934a56d4c52bea2176fe2043a Size/MD5 checksum: 129368 8841e48721472f9a118a94114ba1b711 Size/MD5 checksum: 266562 12f88398bf43564ced08700eded1b570 Size/MD5 checksum: 119316 be8482028921190e5354e7f335a66f35 HP Precision architecture: Size/MD5 checksum: 105338 b7362ed550e20fea8f5c8867e800244e Size/MD5 checksum: 92402 3ab934c17acb2b202353aef5616de7ef Size/MD5 checksum: 103636 8d04530d2f40c1a68f2e73c812f37d95 Size/MD5 checksum: 261052 6175ddce92b702cd985b42a0732d77da Size/MD5 checksum: 91856 416e4246bd81c80416bac08403952147 Motorola 680x0 architecture: Size/MD5 checksum: 72160 e58cac2fafd22f52e0cde1eb03e58305 Size/MD5 checksum: 64286 93862fd1cfd5227b924220204236b3bf Size/MD5 checksum: 69984 d2687445ad4040d3a834ac124db0ef41 Size/MD5 checksum: 257430 9969d085c7a03406cd4a041682ee48f8 Size/MD5 checksum: 64846 52bf70022f19beeff3992c5ba8c149d9 Big endian MIPS architecture: Size/MD5 checksum: 95994 5ce22f670fd6c365590cf3c01f943d65 Size/MD5 checksum: 75596 baed4edf05e024e13fa43e78e2d2a29c Size/MD5 checksum: 92856 01fed4fff973f5a95ea5e6ed3857b91c Size/MD5 checksum: 257976 4eb4d1d665e4b6a7bbf2193f3cc62450 Size/MD5 checksum: 76156 b671f306dd92cf09c4b8a33bab09ce19 Little endian MIPS architecture: Size/MD5 checksum: 96008 9ec179a4564582ce50e6b201777ef23e Size/MD5 checksum: 75648 58f2c0b8afaf6de85e2fede31a4f646e Size/MD5 checksum: 92880 36bb31201c3378a36ac64870974eb73d Size/MD5 checksum: 257858 7053dbfe9e93575221ce9b1d7d467da7 Size/MD5 checksum: 76084 9f9b46e99365b5345dc9b624a570dfe1 PowerPC architecture: Size/MD5 checksum: 94302 fe298503bc148f1b2452658e9b20d05a Size/MD5 checksum: 76954 d041549e2233316af2c69fee546f0103 Size/MD5 checksum: 90412 7526bda3992f49a4c5f3ba58d7cd4fc7 Size/MD5 checksum: 258580 b60916550932d906ab22aa468a021e60 Size/MD5 checksum: 75620 54a8305cf75729c5ac1f214452d3789d IBM S/390 architecture: Size/MD5 checksum: 83428 c77d95990e534abb6213a139ed584a39 Size/MD5 checksum: 78158 dce6c7a0b7bf3b2fdfc2ce7b2ab00bad Size/MD5 checksum: 84282 fc233d461d052cd887e8c939226e55e3 Size/MD5 checksum: 258730 d3d4603f9896edf7f25828e3c8e0fa8e Size/MD5 checksum: 78752 1017bfc272a400c4b3eae7b81527e27d Sun Sparc architecture: Size/MD5 checksum: 88942907dda004f0ac89f62c6efe73440b260 Size/MD5 checksum: 76738 a199f14f830b00fdf675b708941af0aa Size/MD5 checksum: 86010 d247ce63a25491ecdd66e0f2fc3b5f81 Size/MD5 checksum: 258812 e35aae1dbb20da38eab6739b6c2e4e49 Size/MD5 checksum: 77052 90a65aa4776815f7d4414a24a95b514a These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest imlib package for Debian addresses a potential code execution vulnerability by patching a heap overflow issue, thus prompting users to apply the recommended upgrades.. debian, imlib update, code execution fix, heap overflow patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 26, 2005 Critical Debian
87

Debian DSA 618-1: Critical Imlib Buffer Overflow Threat and Update

Pavel Kankovsky discovered that several overflows found in the libXpm library were also present in imlib, an imaging library for X and X11. An attacker could create a carefully crafted image file in such a way that it could cause an application linked with imlib to execute arbitrary code when the file was opened by a victim.. --------------------------------------------------------------------------Debian Security Advisory DSA 618-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze December 24th, 2004 http://www.debian.org/security/faq --------------------------------------------------------------------------Package : imlib Vulnerability : buffer overflows, integer overflows Problem-Type : local/remote Debian-specific: no CVE ID : CAN-2004-1025 CAN-2004-1026 BugTraq ID : 11830 Debian Bug : 284925 Pavel Kankovsky discovered that several overflows found in the libXpm library were also present in imlib, an imaging library for X and X11. An attacker could create a carefully crafted image file in such a way that it could cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2004-1025 Multiple heap-based buffer overflows. CAN-2004-1026 Multiple integer overflows. For the stable distribution (woody) these problems have been fixed in version 1.9.14-2woody2. For the unstable distribution (sid) these problems have been fixed in version 1.9.14-17.1. We recommend that you upgrade your imlib packages immediately. Upgrade Instructions --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-getupgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 805 6b89c44e7635494ab6309f31e8977a71 Size/MD5 checksum: 273298 66b9b193f65f0f552a3c7475504b4aa3 Size/MD5 checksum: 748591 1fa54011e4e1db532d7eadae3ced6a8c Architecture independent components: Size/MD5 checksum: 114710 04c82fdad40b4c81ca6145015d1ca9e7 Alpha architecture: Size/MD5 checksum: 119716 e6b3de272b4ccded198ca1c7a8cbe9c7 Size/MD5 checksum: 97146 afa40cb2097baab7293694292a163373 Size/MD5 checksum: 117364 43f345f06377fefe9a5976a3d571876c Size/MD5 checksum: 262202 2baf347e73e7833f340b72d250709b2f Size/MD5 checksum: 97202 af8d9bcb83596b124cc7148b4b42a612 ARM architecture: Size/MD5 checksum: 94088 97cab67730bda9ca0a83ff1e8fd646c7 Size/MD5 checksum: 75402 db81fe94e6b35c3baa2505f533f6aa01 Size/MD5 checksum: 94136 d6d974eb4fb709141cd8482b45756a74 Size/MD5 checksum: 258262 da89d3962a56d4d37bcb4084e5ae4176 Size/MD5 checksum: 76330 b1f75f5cc08f4175b72ba932c7b34210 Intel IA-32 architecture: Size/MD5 checksum: 77884 c24a0ebb06c178eb4d473c20433b7389 Size/MD5 checksum: 69338 b284172f465ac35e7fdf44bea07504e8 Size/MD5 checksum: 76452 acaaca70c492ee827d678743dd990d61 Size/MD5 checksum: 258354 790ada2bfc6205c0cd43459ae95fb127 Size/MD5 checksum: 69730 05f8b9bbab5f9008599f2fa37caaed2c Intel IA-64 architecture: Size/MD5 checksum: 129024 a059b5c1e0411f389c2fd39e594f5b5a Size/MD5 checksum: 116312 9eb937b6c56c0237487b2bf2e84eed4f Size/MD5 checksum: 129156 c726f93cf1456230e99ac2c03783080f Size/MD5 checksum: 26651087aee70d85386bd2c29ee89b76360c75 Size/MD5 checksum: 119094 026ac0e934b06183ee32f46cb70dbe76 HP Precision architecture: Size/MD5 checksum: 105152 1cdbb634730781005e656d4a6f45afe4 Size/MD5 checksum: 92194 902a728a355b9090c76083e49240111c Size/MD5 checksum: 103532 e86528e832c62b21b90e4d1a15c5821f Size/MD5 checksum: 261002 f39d5a52457a8a348d7881a649450fe3 Size/MD5 checksum: 91622 efec147e4b6fb0bfb0d6510359dcd6a3 Motorola 680x0 architecture: Size/MD5 checksum: 72004 3cb969b4018031188492c6bc448705dc Size/MD5 checksum: 64146 8bbbf2e8b4f7c31aa4e302dffe35ad71 Size/MD5 checksum: 69820 8d7d31a6c3a44f7a3dcb5c0e17fc7bca Size/MD5 checksum: 257372 52888389b545dc1e3cce3b899a65a2d4 Size/MD5 checksum: 64660 86ed5f17d0a2ab99c8775619b451cb17 Big endian MIPS architecture: Size/MD5 checksum: 95756 615f2919772c3278475db2a123e10365 Size/MD5 checksum: 75404 04fc84337f3cc79da350e63e54c0bd39 Size/MD5 checksum: 92638 fc95257f5614e0ca9000083d0863e23e Size/MD5 checksum: 257934 43d3ab6970888d80aca888a90fc3b9dc Size/MD5 checksum: 75948 45b966a81a0bc4fdad17776491eebfbb Little endian MIPS architecture: Size/MD5 checksum: 95806 5d8184b2fa877b5140df8cd4f05bc629 Size/MD5 checksum: 75478 54248fbb3244f95da8bd1a5e0dcc64c2 Size/MD5 checksum: 92688 ba0e8f951706a1642ab2994a11113a0c Size/MD5 checksum: 257834 99d601494d76618f8974b05ba3f21401 Size/MD5 checksum: 75884 856fed2b0af1665d36a7ac76dc4516a4 PowerPC architecture: Size/MD5 checksum: 94166 ce1b5d6adc54b226054a2fbd83b2a86d Size/MD5 checksum: 76854 ba841bf89a7af734b741a33a591cab8f Size/MD5 checksum: 90276 23d95df53d747a550721960c673e8d9f Size/MD5 checksum: 258522 4619a569bcb42a6ff4e691a9a73b4298 Size/MD5 checksum: 754321f72571029157018583561cd829f47b1 IBM S/390 architecture: Size/MD5 checksum: 83314 ba3c9382fe7b468b74e36f8cd4eece90 Size/MD5 checksum: 78052 2eb2a4951c05bedbe5e131b8f6ecc3eb Size/MD5 checksum: 84168 9de33add121dc1d258389522c0456544 Size/MD5 checksum: 258680 909968f199ff27b6f6a51712043925d9 Size/MD5 checksum: 78622 9eb679c1377078e6065f8f0183388a70 Sun Sparc architecture: Size/MD5 checksum: 88778 d37e329386b3b5c9514fb9619175e75f Size/MD5 checksum: 76534 23476af1594709264a14e72a301bd747 Size/MD5 checksum: 85812 74c633ae47eab66ee3402b9b3f8329b5 Size/MD5 checksum: 258760 87f9a03a2528ff6dce1008ad9a7e1392 Size/MD5 checksum: 76790 db539c8ee1aff2573c2e54bb525468fc These files will probably be moved into the stable distribution on its next update. ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian's advisory points out critical vulnerabilities in imlib that could allow arbitrary code execution. Users should update promptly to secure their systems. Debian Security Advisory, Imlib Buffer Overflow, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 24, 2004 Critical Debian
87

Debian: DSA 548-1 Critical Heap Overflow Vulnerability in Imlib

Marcus Meissner discovered a heap overflow error in imlib, an imaginglibrary for X and X11, that could be abused by an attacker to executearbitrary code on the vicims machine.. -------------------------------------------------------------------------- Debian Security Advisory DSA 548-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze September 16th, 2004 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : imlib Vulnerability : unsanitised input Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0817 Marcus Meissner discovered a heap overflow error in imlib, an imaging library for X and X11, that could be abused by an attacker to execute arbitrary code on the vicims machine. For the stable distribution (woody) this problem has been fixed in version 1.9.14-2wody1. For the unstable distribution (sid) this problem has been fixed in version 1.9.14-17 of imlib and in version 1.9.14-16 of imlib+png2. We recommend that you upgrade your imlib1 packages. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 803 6472ca2afec2286f184350d849bf9a5d Size/MD5 checksum: 269552 31472b9a33f689d518c237fa7d742961 Size/MD5 checksum: 748591 1fa54011e4e1db532d7eadae3ced6a8c Architecture independent components: Size/MD5 checksum: 114576 15b012593229931c4bbc29040d2fdae5 Alphaarchitecture: Size/MD5 checksum: 119104 4e64b397ae2e9a839600fc8f19fdd1df Size/MD5 checksum: 96582 a0f07e9f4ded557eb3fabc0914ea6625 Size/MD5 checksum: 116752 d036103895155f0267a26283631978d5 Size/MD5 checksum: 262078 5e49dc13a1a4d61f74222dc1ae1bcb57 Size/MD5 checksum: 96668 b4cff88f951f6682358f6f393691a5bd ARM architecture: Size/MD5 checksum: 93592 9c928508c6366fa367cddaecf4d2e99d Size/MD5 checksum: 75032 4f90fccb7d8bc12b188d62da43f8f712 Size/MD5 checksum: 93634 1c44359a8043ecd94dbcd7a4349fac6a Size/MD5 checksum: 258134 5f10db2bcb55a1ef8de534bdd0be730a Size/MD5 checksum: 75924 87ff486de47e594a996992a8721c9542 Intel IA-32 architecture: Size/MD5 checksum: 77454 2b01b6df4f0859f6975932d2c3889fef Size/MD5 checksum: 68730 afaadff6f4e14d885a663bd47c68c97a Size/MD5 checksum: 76038 3b541785c7423bbb1c08b7ab4195f25d Size/MD5 checksum: 258222 89e8b55aac576760bb7dbd2fbce97ef4 Size/MD5 checksum: 69332 1a2f9af32e10060af9712309565de823 Intel IA-64 architecture: Size/MD5 checksum: 128272 be9e12e56078ad9426c018fd589a386c Size/MD5 checksum: 115640 2894139657c170641f026a5f51be8ae4 Size/MD5 checksum: 128662 a0d502bd1cb1147ec2806739dab6ffd9 Size/MD5 checksum: 266378 5febdea31eb17b29854233fbfb307869 Size/MD5 checksum: 118478 b53e063c50cbee0082fd3f34e6495a07 HP Precision architecture: Size/MD5 checksum: 104722 cd83de0a77ec1a2e9ad2b89661f7ce95 Size/MD5 checksum: 91568 e7ea261ab12d3026c655b88816b03fb1 Size/MD5 checksum: 103092 787e38c5c6804290826fb24d39942471 Size/MD5 checksum: 260886 6b7d99f18c2c4e531268d0685cec7815 Size/MD5 checksum: 91038 c8ca84e673418e3c0be7fd6f983b72a5 Motorola 680x0 architecture: Size/MD5 checksum: 71648 46ee28536a1eca2cde30c8956aced176 Size/MD5 checksum: 63886 c27cb2052b30443ccbd8aaa1ee70752c Size/MD5 checksum: 69480 62a8fdc6b8eefdf233073d27ff143159 Size/MD5 checksum: 257254 2062e2c1e836765fa547540c25217dc0 Size/MD5 checksum: 64098 bb634b1f3812b538a158fcb5ffb2037a Big endian MIPS architecture: Size/MD5 checksum: 95334 6df97ffb427a10ea4ad53b9031725fca Size/MD5 checksum: 75042 dc6945a5f284fe9df84f73aef5c5fd98 Size/MD5 checksum: 92272 77d49cb7e43d26ff1c760f509b68a692 Size/MD5 checksum: 257824 03abbd17269e50822da7d9ff8962500d Size/MD5 checksum: 75606 6173739a1120d7388a77727ee28a1c50 Little endian MIPS architecture: Size/MD5 checksum: 95350 af89cfadec5bbb4e48f9ae0bb6c59b03 Size/MD5 checksum: 75088 340cedde5a835f610164753e64d8a36d Size/MD5 checksum: 92286 48df55c16c2760bd82d5dfbd051d1104 Size/MD5 checksum: 257692 f9b42b3f6d6ba9e4bdc48df5fe5c2d22 Size/MD5 checksum: 75520 2c8d731adcee92a92307fd11861fdaae PowerPC architecture: Size/MD5 checksum: 93706 6cc8b8753c18f11793805faeeb25aded Size/MD5 checksum: 76440 50d611afb959762e4b975bdf181dabe4 Size/MD5 checksum: 89862 cbf553ff94b438dccea73bd68cb64f8f Size/MD5 checksum: 258394 2cbbcc991c068aa94adff360210dfc41 Size/MD5 checksum: 75050 8e123dbbfc8e0ad2ec3acf21619f4658 IBM S/390 architecture: Size/MD5 checksum: 82924 5fff2f003dcd49d4786f09210b76df35 Size/MD5 checksum: 77602 270ce2d438f02793c50f3f27dc26c872 Size/MD5 checksum: 83804 6413991452e5bee44855606146c3402d Size/MD5 checksum: 258558 0f331b840d6f82164f4869ee4d9847d7 Size/MD5 checksum: 78164 521720c8c47a87ef9c768108ec9bffed Sun Sparc architecture: Size/MD5 checksum: 88346 7e8d46b4b7af331e92dc8bc40e1af3f1 Size/MD5 checksum: 76190 14d67fc9827d7eae2533c4ff3ad048b3 Size/MD5 checksum: 85312 5c8b26804737b09678f60ef9ea4048ba Size/MD5 checksum: 258638 c2577ef0cc83d0934778c2eec3d106e3 Size/MD5 checksum: 76356 f500ce8f5cf4f16de487c1677970eccb These files will probably be moved into the stable distribution on its next update. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical heap overflow in imlib could allow attackers to execute code. Update to mitigate risks associated with this flaw.. imlib exploit, heap overflow risk, debian update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 16, 2004 Critical Debian
98

Red Hat Enterprise Linux: RHSA-2004:465-01 Critical: Imlib Heap Overflow

An updated imlib package that fixes several heap overflows is now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated imlib package fixes security vulnerability Advisory ID: RHSA-2004:465-01 Issue date: 2004-09-15 Updated on: 2004-09-15 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0817 --------------------------------------------------------------------- 1. Summary: An updated imlib package that fixes several heap overflows is now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: Imlib is an image loading and rendering library. Several heap overflow flaws were found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it could cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the SystemAdministration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 130909 - CAN-2004-0817 heap overflow in BMP decoder 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm ia64: ca8f753c817cbe0bf24ac0ac2b03bccc imlib-1.9.13-4.2.ia64.rpm 11060c4560ee42e3e9e0e482a88189c2 imlib-cfgeditor-1.9.13-4.2.ia64.rpm 11e6bd0ee4caca73cbc0ddc80bf1d793 imlib-devel-1.9.13-4.2.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm ia64: ca8f753c817cbe0bf24ac0ac2b03bccc imlib-1.9.13-4.2.ia64.rpm 11060c4560ee42e3e9e0e482a88189c2 imlib-cfgeditor-1.9.13-4.2.ia64.rpm 11e6bd0ee4caca73cbc0ddc80bf1d793 imlib-devel-1.9.13-4.2.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 70350a36d0e898640bf0370f74d26329 imlib-1.9.13-4.2.src.rpm i386: 977d25ef2ed5d80a3d752bcc309dcea3 imlib-1.9.13-4.2.i386.rpm 4ca29312814b0c29e87acb6c1eba4f31 imlib-cfgeditor-1.9.13-4.2.i386.rpm ab03d718bd43a82cd4fa77118915ca7b imlib-devel-1.9.13-4.2.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm ppc: 3d5eae85598168b6e337a0689eb2d743 imlib-1.9.13-13.3.ppc.rpm c9bd4375d8e077fcc70a638804d16b65 imlib-devel-1.9.13-13.3.ppc.rpm s390: 17404e9fdddd26a89d81df23e3aae7db imlib-1.9.13-13.3.s390.rpm 5a3c49f094187deb72b9c522fedd5724 imlib-devel-1.9.13-13.3.s390.rpm s390x: 81d3bbb3472454bd14c748c60c219d2b imlib-1.9.13-13.3.s390x.rpm 7e6739f7b72993dadbc4a489898c83c1 imlib-devel-1.9.13-13.3.s390x.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Desktop version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 6b77190f47b54d9c4c8bfc59cb5c9a97 imlib-1.9.13-13.3.src.rpm i386: ead45a05f882e533d8967caad278a3ff imlib-1.9.13-13.3.i386.rpm fb55305b96a608e4a59d734f0c933505 imlib-devel-1.9.13-13.3.i386.rpm ia64: 9444828842659c3bec047cc18d2528ee imlib-1.9.13-13.3.ia64.rpm c559153e239abff5269e41c30233ca05 imlib-devel-1.9.13-13.3.ia64.rpm x86_64: a541f53f7ae3b301598828d05014b46e imlib-1.9.13-13.3.x86_64.rpm ab80ef08fb5a847a729c8d69640c8366 imlib-devel-1.9.13-13.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: Bug 151034 – buffer overflow in bmp handling CVE -CVE-2004-0817 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . The updated imlib framework tackles significant buffer overflow issues within Red Hat environments, enhancing the overall protective strategies.. Red Hat Enterprise Linux, imlib heap overflow, critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 15, 2004 Critical Red Hat
89

Fedora Core 1: 2004-300 Moderate: Imlib Heap Overflow Risk

Several heap overflow vulnerabilities have been found in the imlib BMPimage handler. An attacker could create a carefully crafted BMP file insuch a way that it would cause an application linked with imlib toexecute arbitrary code when the file was opened by a victim.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-300 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : imlib Version : 1.9.13 Release : 15.fc1 Summary : An image loading and rendering library for X11R6. Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. You may also want to install the imlib-cfgeditor package, which will help you configure Imlib. --------------------------------------------------------------------- Update Information: Several heap overflow vulnerabilities have been found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to these issues. --------------------------------------------------------------------- * Thu Sep 09 2004 Matthias Clasen - Security fixes --------------------------------------------------------------------- This update can be downloaded from: ... 03a77921e2efd86e0703d66de59cad1c SRPMS/imlib-1.9.13-15.fc1.src.rpm 7c819092b3f54e6fba51460f10d4d2db x86_64/imlib-1.9.13-15.fc1.x86_64.rpm 296479ab2f3ebfdb1b43c4454d881009 x86_64/imlib-devel-1.9.13-15.fc1.x86_64.rpm 5b66680b22684df822ef4f38d6e87a35 x86_64/imlib-cfgeditor-1.9.13-15.fc1.x86_64.rpm f211ba31e2b13a872d0c318b4892c624 x86_64/debug/imlib-debuginfo-1.9.13-15.fc1.x86_64.rpm 8bd4bb9bbcad02a8442edd5bd6afd8f2 i386/imlib-1.9.13-15.fc1.i386.rpm 469d4ed01e2ba0b49fdcd0fa01323052 i386/imlib-devel-1.9.13-15.fc1.i386.rpm fa26f3f2c7a877c806b675fc8de68203 i386/imlib-cfgeditor-1.9.13-15.fc1.i386.rpm 7d0d786eb8e5ea9793c2505267a2f650 i386/debug/imlib-debuginfo-1.9.13-15.fc1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Reevaluate the memory management strategies in the BMP processing module of imlib to mitigate buffer overflow risks and safeguard Fedora users from exploitation threats. Fedora Security Update, Imlib Patch, BMP Image Handler Fix, Core 1 Security. . LinuxSecurity.com Team

Calendar 2 Sep 10, 2004 Fedora
89

OpenSUSE: OPENSUSE-2005-400 Critical: Imlib Buffer Overrun Issue

Several heap overflow vulnerabilities have been found in the imlib BMPimage handler.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-300 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : imlib Version : 1.9.13 Release : 15.fc1 Summary : An image loading and rendering library for X11R6. Description : Imlib is a display depth independent image loading and rendering library. Imlib is designed to simplify and speed up the process of loading images and obtaining X Window System drawables. Imlib provides many simple manipulation routines which can be used for common operations. Install imlib if you need an image loading and rendering library for X11R6, or if you are installing GNOME. You may also want to install the imlib-cfgeditor package, which will help you configure Imlib. --------------------------------------------------------------------- Update Information: Several heap overflow vulnerabilities have been found in the imlib BMP image handler. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with imlib to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0817 to this issue. Users of imlib should update to this updated package which contains backported patches and is not vulnerable to these issues. --------------------------------------------------------------------- * Thu Sep 09 2004 Matthias Clasen - Security fixes --------------------------------------------------------------------- This update can be downloaded from: 03a77921e2efd86e0703d66de59cad1c SRPMS/imlib-1.9.13-15.fc1.src.rpm 7c819092b3f54e6fba51460f10d4d2db x86_64/imlib-1.9.13-15.fc1.x86_64.rpm 296479ab2f3ebfdb1b43c4454d881009 x86_64/imlib-devel-1.9.13-15.fc1.x86_64.rpm 5b66680b22684df822ef4f38d6e87a35 x86_64/imlib-cfgeditor-1.9.13-15.fc1.x86_64.rpm f211ba31e2b13a872d0c318b4892c624 x86_64/debug/imlib-debuginfo-1.9.13-15.fc1.x86_64.rpm 8bd4bb9bbcad02a8442edd5bd6afd8f2 i386/imlib-1.9.13-15.fc1.i386.rpm 469d4ed01e2ba0b49fdcd0fa01323052 i386/imlib-devel-1.9.13-15.fc1.i386.rpm fa26f3f2c7a877c806b675fc8de68203 i386/imlib-cfgeditor-1.9.13-15.fc1.i386.rpm 7d0d786eb8e5ea9793c2505267a2f650 i386/debug/imlib-debuginfo-1.9.13-15.fc1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Multiple buffer overflow vulnerabilities in imlib may lead to arbitrary code execution. Upgrade Fedora for safety.. Imlib Security Update, Heap Overflow, Fedora Core Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 09, 2004 Critical Fedora
91

Gentoo Linux 200409-12: Normal Severity Buffer Overflow in ImageMagick

ImageMagick, imlib and imlib2 contain exploitable buffer overflow vulnerabilities in the BMP image processing code.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ImageMagick, imlib, imlib2: BMP decoding buffer overflows Date: September 08, 2004 Bugs: #62309, #62487 ID: 200409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= ImageMagick, imlib and imlib2 contain exploitable buffer overflow vulnerabilities in the BMP image processing code. Background ========= ImageMagick is a suite of image manipulation utilities and libraries used for a wide variety of image formats. imlib is a general image loading and rendering library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/imagemagick < 6.0.7.1 > = 6.0.7.1 2 media-libs/imlib < 1.9.14-r2 > = 1.9.14-r2 3 media-libs/imlib2 < 1.1.2 > = 1.1.2 ------------------------------------------------------------------- 3 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Due to improper bounds checking, ImageMagick and imlib are vulnerable to a buffer overflow when decoding runlength-encoded bitmaps. This bug can be exploited using a specially-crafted BMP image and could potentially allow remote code executionwhen this image is decoded by the user. Impact ===== A specially-crafted runlength-encoded BMP could lead ImageMagick and imlib to crash or potentially execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All ImageMagick users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-gfx/imagemagick-6.0.7.1" # emerge "> =media-gfx/imagemagick-6.0.7.1" All imlib users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-libs/imlib-1.9.14-r2" # emerge "> =media-libs/imlib-1.9.14-r2" All imlib2 users should upgrade to the latest version: # emerge sync # emerge -pv "> =media-libs/imlib2-1.1.2" # emerge "> =media-libs/imlib2-1.1.2" References ========= [ 1 ] CAN-2004-0817 https://www.cve.org/CVERecord?id=CAN-2004-0817 [ 2 ] CAN-2004-0802 https://www.cve.org/CVERecord?id=CAN-2004-0802 [ 3 ] ImageMagick Mailing List [ 4 ] SecurityTracker #1011104 [ 5 ] SecurityTracker #1011105 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200409-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Using GnuPG with Thunderbird - iD8DBQFBPsrXvcL1obalX08RAiMWAJ9jRgAsJDcmL5JF/EZrn0BREPo5egCgpomO W24qtwrG1lisZYBSGyyWrRI=XLhl -----END PGP SIGNATURE----- . Recent security flaws in ImageMagickand Imlib might enable attackers to execute arbitrary code through specially designed BMP image files.. ImageMagick, imlib, buffer overflow, security advisory, Gentoo. . LinuxSecurity.com Team

Calendar 2 Sep 08, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here