Peter Valchev (Google Security) discovered a series of integer overflow weaknesses in Cairo, a vector graphics rendering library used by many other applications. If an application uses cairo to render a maliciously-crafted PNG image, the vulnerability allows the execution of arbitrary code. . - ------------------------------------------------------------------------Debian Security Advisory DSA-1542-1
USN-550-1 fixed vulnerabilities in Cairo. A bug in font glyph rendering was uncovered as a result of the new memory allocation routines. In certain situations, fonts containing characters with no width or height would not render any more. This update fixes the problem. We apologize for the inconvenience. . =========================================================== Ubuntu Security Notice USN-550-3 December 13, 2007 libcairo regression https://bugs.launchpad.net/ubuntu/+source/libcairo/+bug/175573 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libcairo2 1.0.4-0ubuntu1.2 Ubuntu 6.10: libcairo2 1.2.4-1ubuntu2.2 Ubuntu 7.04: libcairo2 1.4.2-0ubuntu1.3 Ubuntu 7.10: libcairo2 1.4.10-1ubuntu4.4 After a standard system upgrade you need to restart your session to effect the necessary changes. Details follow: USN-550-1 fixed vulnerabilities in Cairo. A bug in font glyph rendering was uncovered as a result of the new memory allocation routines. In certain situations, fonts containing characters with no width or height would not render any more. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Peter Valchev discovered that Cairo did not correctly decode PNG image data. By tricking a user or automated system into processing a specially crafted PNG with Cairo, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 21759 e41fe630a06c82f9a7f977ace3b72098 Size/MD5: 7586c51cf24a74fedd37809e4cc1a7b2f9d Size/MD5: 1475777 9002b0e69b3f94831a22d3f2a7735ce2 Architecture independent packages: Size/MD5: 249090 b47a8a55394e4d80991ee7e113a7319a amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 379432 db1755dd03cb6872c8812fb95a70fda6 Size/MD5: 325784 6aa35609e35bd3e585f9c2d8676c41ed i386 architecture (x86 compatible Intel/AMD): Size/MD5: 349960 c7e8786bf619a5b56ccdc52476495e23 Size/MD5: 306244 a8b8718de3cae9481c414f8f02ba5353 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 358940 13a0175de8bc77610a04cba052096d52 Size/MD5: 310650 e85d295192c6f6e519d20cd28688f173 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 345040 40d3cccf5874925daa67421ee0ab90dc Size/MD5: 300000 90be630d2e3fcaa03ba18169c5f7a40c Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 25217 b27d11953aa5ffdb1820ebd03c18c701 Size/MD5: 896 6b639fbaa3718b35a0f51f23ac086788 Size/MD5: 2882781 1222b2bfdf113e2c92f66b3389659f2d Architecture independent packages: Size/MD5: 299434 a8124a9014a71d7586d9f4bb45ad1977 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 416962 a27dbbca13a988d71677e8ac099095ad Size/MD5: 356808 1cc7ed2a382a28f2957a307c40fb9d0a Size/MD5: 471606 c147c040284d2780e76a3ecc0bb7b19a Size/MD5: 395860 de175306f72fd05d9455d742ffa37e59 Size/MD5: 158538 42e94f99b1cccb1a95f9fc3cdb6cfa17 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 399782 f0c7f8196fd61e6b92a505c3261ed972 Size/MD5: 348336 c2914ccbbde0afd38d9118c4bdccd977 Size/MD5: 446514 8c1c1ee01f3becf3e461f25792c1d017 Size/MD5: 385636 2b838294cc98af8002ba7f449f3b548d Size/MD5: 150090 7a70e041387b1af79661c5aeff7202f6 powerpc architecture(Apple Macintosh G3/G4/G5): Size/MD5: 401070 34786d08cd917bd16e07cf225987a620 Size/MD5: 345396 a47e32ca6af8e3ad2790e361253a97f6 Size/MD5: 455332 50fb017f4eef8d65a6a6e2ebe757f1ea Size/MD5: 383174 61d2144a7d06c05683bcb92365aa8a9d Size/MD5: 146982 7d8afc1573aba11efb65584f7cd5f059 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 383912 c623fd762b477c37fcaa1ca2bcb18cf0 Size/MD5: 333300 3c780eaba574fbed0bcf1ace23f2df54 Size/MD5: 432132 ced7984d0cb0caf9652c4f75b521797e Size/MD5: 369110 e1a57ff50fa5719fbeef537c7cab2b8c Size/MD5: 135032 bb15b511c6ba0b5af0d393abf7c1574a Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 29768 4a876d28110b1a3424f13da8203b156a Size/MD5: 980 60227257968f24dbd908b70cfd998a0a Size/MD5: 3081092 b254633046eafe603776d0bee791b751 Architecture independent packages: Size/MD5: 329292 5a2ef8b496d2b39e7c0a30f56a5ec4b2 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 515290 dc95d2e57e217895efad772edf0e2b78 Size/MD5: 430516 5283fd6ecfcbe75a8c6e7a0178074292 Size/MD5: 537344 c9a42b6ed850f3b2aebbb76ab06eee84 Size/MD5: 446332 9a87b277055410f469e38247e3fddc02 Size/MD5: 214120 928e936dd1345e82af7639a4e7f063cd i386 architecture (x86 compatible Intel/AMD): Size/MD5: 489076 b7e1ebf69179067c25fb6f30f5cf527e Size/MD5: 420370 dab0ec21be7bc7ff5dca987465f266aa Size/MD5: 508982 569e7c392ea3a3496891390bc9ee7165 Size/MD5: 435944 7bc22d4300415b54adbd0288c8821170 Size/MD5: 204148 ae40b67f9ea8d8103bdb15ae38645dbc powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 498570 11f55dc91143a6d0c23bdcf668ab8329 Size/MD5: 423184 843707e16edccb864293512f6b39c3b2 Size/MD5: 520668d56ec59cfb635d7be49f394b78e1cd48 Size/MD5: 439108 25879c0110630948fbb77a823be74a41 Size/MD5: 206988 ca62a53a772092f28e6b1f9fa824711a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 472324 99f77ed05576732e8ee73d7d096fed44 Size/MD5: 402526 a8e53a33b1c4d3ee50bde4527a9cefc2 Size/MD5: 492546 43b46a92a315073d18cc951826ad4956 Size/MD5: 417468 6c85ab3d1c3bdb8499eb612c419b9739 Size/MD5: 186278 ef8b4a646415a911ff870b2a5b6e16ed Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 36111 6c63566f300719be4da7a0bcac09075d Size/MD5: 1013 a988294356e56089f185f29bdcb5ae0d Size/MD5: 3216689 5598a5e500ad922e37b159dee72fc993 Architecture independent packages: Size/MD5: 407892 1e9ad8fa3de85f6f2f50f3278928f341 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 572456 992d9deed2678d330b6c0d254f775dae Size/MD5: 489386 dbe2ea733a7c072891269551aa7177ba Size/MD5: 633054 94340a3751ba5b35911a34b42d0b53c3 Size/MD5: 537180 ba458194ce4234a1e7735e34705c998d Size/MD5: 195868 d288b4d3a3feb119a20595ccec9cd6f8 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 546768 ce0e739d1d19d8fc29c88d72bbfa5b6c Size/MD5: 479970 798eb7fc786c5d0759215f462252c8df Size/MD5: 601468 ef0f0772ab913e8695b53dccb56494b6 Size/MD5: 524340 a418f4341d95ed191415b5d2365bd586 Size/MD5: 186454 8485e6b8030f52f62c6a905cab3352e1 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 555094 258ea4c57683624d80c8cb8e6c544b70 Size/MD5: 479242 e23bc3b619bc533d25eb9873bb6e68b4 Size/MD5: 614090 cd5520db5b878821d52ed13ad69747b7 Size/MD5: 528694 5416ec8f3f67c509fc52b3f01f22b96b Size/MD5: 186298 b6a9fd722001d6fcd0987b3a88503f99 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 543968 126b4d740f9ad684c6e47c286b87afc8 Size/MD5: 471474 e897822f36019d17501472bc9b6c4791 Size/MD5: 585030 c0cf996cb88ed74b0886f76ec35cc7b7 Size/MD5: 505554 f20daf037a08ad67b818c98ad7717bea Size/MD5: 177700 79888f6855ad4b9b64741c955b0581fd . Ubuntu Security Notification USN-551-4 addresses a serious vulnerability in libjpeg image processing library impacting several versions.. libcairo issue, Ubuntu update, security patch, font rendering, bug fix. . Severity: Critical. LinuxSecurity.com Team
Peter Valchev discovered that Cairo did not correctly decode PNG image data. By tricking a user or automated system into processing a specially crafted PNG with Cairo, a remote attacker could execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-550-2 December 10, 2007 libcairo regression ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.04: libcairo2 1.4.2-0ubuntu1.2 Ubuntu 7.10: libcairo2 1.4.10-1ubuntu4.2 After a standard system upgrade you need to restart your session to effect the necessary changes. Details follow: USN-550-1 fixed vulnerabilities in Cairo. The upstream fixes were incomplete, and under certain situations, applications using Cairo would crash with a floating point error. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Peter Valchev discovered that Cairo did not correctly decode PNG image data. By tricking a user or automated system into processing a specially crafted PNG with Cairo, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 29170 a64d5accaf670a3a042a0716291394d7 Size/MD5: 980 f4568de7fd8d8e64448dd1132927061f Size/MD5: 3081092 b254633046eafe603776d0bee791b751 Architecture independent packages: Size/MD5: 329056 b1575fd670eb3855e96edf52f3cf7ab0 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 515040 59fc61a32d6c5ca65df42f268268f379 Size/MD5: 4302666d63671bf6d432855a177a76cab4f1d0 Size/MD5: 537122 59f7f0831b4553b99b533958b2a5637d Size/MD5: 446134 17a75ebfeaa43eca5075260f7322e604 Size/MD5: 214084 e25a10d4d4e773a7a6a81e4222116497 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 488790 979721dacfc63ff1e87c97d104355108 Size/MD5: 420138 074aafcb523bc8b393ff13513ed94f81 Size/MD5: 508712 6a177d9cffabeb7b46d0b1b1d83408bd Size/MD5: 435692 ff8716999c992cde0d53c0a4cd7776fb Size/MD5: 204116 519465ff73b0dead2e18ecef8090c41f powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 498406 cac5ffc403e3d286be56aa4c7dfcac03 Size/MD5: 422954 313dccc5f8880eb99d2bd520dd6b1981 Size/MD5: 520498 0c0472153c4b798e2219c3e72643818a Size/MD5: 438856 645c36b71f069a29c78e71517ebc9253 Size/MD5: 206976 d4d191ab373dae4bc9b61b4c72aefef4 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 472108 0317c9ca17ab5428f9e1f359cfb2fa06 Size/MD5: 402336 44be030c98706251b3e414f3e89a9154 Size/MD5: 492324 634481a6f873ae9c00b8b1a416b4ea7e Size/MD5: 417212 f96fd87530823ee7aa2e6870049eb45f Size/MD5: 186296 42df2b3d472069e4918a717c964ba7f7 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 35820 a5dae2b600de79eb6d6cd7c0df613554 Size/MD5: 1013 8474af5f122f83ab1f75f9ea3f8d354e Size/MD5: 3216689 5598a5e500ad922e37b159dee72fc993 Architecture independent packages: Size/MD5: 407696 c269f047a06167c111ee0a11365cc1ea amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 572210 a9642cb123ccf6312916e22c27a6e3a9 Size/MD5: 489124 4924ec45a4eea3a3a275f002415653e2 Size/MD5: 632822 07662831762f20e50139b5c950731f58 Size/MD5: 536922 99d1a0202e50db78c0c4646859fea13f Size/MD5: 195802c81baf7740526b9ed2264ab2d5be8bc0 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 546548 529e9341682d12e757d0e5dc686cc6ec Size/MD5: 479746 5769a4e61e6422cc12839ff17925de9f Size/MD5: 601216 d54be2b3a904bfa20af22b69d8fd21ea Size/MD5: 524124 53f686c49d846e1afe5e8f89115fa1d2 Size/MD5: 186428 c84079451a7bfc3b85c34238aa3c78ce powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 554832 1de0e3112f48e32b64840429ba621e23 Size/MD5: 479018 4980ba793084c17f733f40bbf8e4f15e Size/MD5: 613880 9a7e834124d8a124f8408ed89f2353da Size/MD5: 528508 5ae830818a92c4838fc3951485431530 Size/MD5: 186266 098d9b7df582a4ecb9bdf77831c4336a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 543772 e1ea0f5cb6745b0272a6c4d4aeb239e3 Size/MD5: 471248 a8e5991f36e20b71e6213d6c44031e37 Size/MD5: 584786 affc097d3d1a068fd5fd7f80d13005c0 Size/MD5: 505364 0a59d599ca6fb9f8047d35745c0d0db3 Size/MD5: 177688 f2705635217a2476cadc8b6dc5b9eae6 . Addressing the libcairo PNG image vulnerability in Ubuntu to enhance system protection and prevent unapproved code execution.. libcairo Security, Ubuntu Update, PNG Exploit. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.