Login
Newsletter
Werbung

Sicherheit: Denial of Service in GDK-PixBuf
Aktuelle Meldungen Distributionen
Name: Denial of Service in GDK-PixBuf
ID: USN-4743-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Mo, 22. Februar 2021, 22:10
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20240
Applikationen: Gtk+

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5822851026416491652==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="ZuQnUV7ZIEZITTFadIFgPhuamujVjTPjT"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--ZuQnUV7ZIEZITTFadIFgPhuamujVjTPjT
Content-Type: multipart/mixed;
boundary="INGvxnBHPT2kR2zhdGM3R6uoGEsvvtOIS";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <682e5742-e4a6-0a28-a05b-61197f004742@canonical.com>
Subject: [USN-4743-1] GDK-PixBuf vulnerability

--INGvxnBHPT2kR2zhdGM3R6uoGEsvvtOIS
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4743-1
February 22, 2021

gdk-pixbuf vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS

Summary:

GDK-PixBuf could be made to crash if it opened a specially crafted file.

Software Description:
- gdk-pixbuf: GDK Pixbuf library

Details:

It was discovered that the GDK-PixBuf library did not properly handle
certain GIF images. If an user or automated system were tricked into
opening a specially crafted GIF file, a remote attacker could use this flaw
to cause GDK-PixBuf to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
libgdk-pixbuf2.0-0 2.40.0+dfsg-5ubuntu0.2

Ubuntu 20.04 LTS:
libgdk-pixbuf2.0-0 2.40.0+dfsg-3ubuntu0.2

After a standard system update you need to restart your session to make all
the necessary changes.

References:
https://usn.ubuntu.com/4743-1
CVE-2021-20240

Package Information:
https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.40.0+dfsg-5ubuntu0.2
https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.40.0+dfsg-3ubuntu0.2


--INGvxnBHPT2kR2zhdGM3R6uoGEsvvtOIS--

--ZuQnUV7ZIEZITTFadIFgPhuamujVjTPjT
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmAz0C4ACgkQZWnYVadE
vpMDrRAAkk+7oyhaTJN0Cznk0WQHIqSTT20WWcqPZJcfLtrrfQ5d9wbl6c/AW/KV
HHJ0rH5428lN2ZcfhLhiNI9iUqCptHjW0DpDkrZoMGP676/D2NcWQ5rWghECXLDY
FyA4LSWK9uGJJrybgfzSuGv0GtMDywC8HYPV3Ztd2kRDd5uW67lvUNIG5Ud5arep
mk1YvZquvsNjKLLZ0TZ+bzQepYsXJ2w/s7TSOEzt4BVDFcPp6ZwbvUB7mQN1zkWG
G2Ee03HYqjzh4RiyDOA3DjiTjyauqaBw9+bP1o1bgOltHqY+rKuGA4yjECKpTI3+
Yx8BOwTLF31Mnj/paag8S0UVHezhaT+34tLMQ+zZQ62IF1mrOTCIjpNCrD2LSPYx
ejcEC0rQaB1igkz8V76oYCJ1u6NtEUwi0SvNIcNyHmrOz259ADRgxmOFMJcmxa44
YsN49awQPYAeF3Lh/xJI4QvqHjafQR0Y3vl/8LXtWybkeO7BY0gz+BTPM7SV4d94
5Ssatj++hRWnRCHCmlf6gQvJ2uyQ3HEO7THin6haX6BUja/y8AfFZ3GLmA/q+Uy9
Myls60o95y6UxkAgCC12ScSyJaHdvrPzmekPwSew6Zdz3lHgVUCliFxX9kqpm+l8
U02yVTrY1lxlb1X9pYzeDtcuG4wUqDD63u7h8YXx9agLpkhoZ68=
=Xfap
-----END PGP SIGNATURE-----

--ZuQnUV7ZIEZITTFadIFgPhuamujVjTPjT--


--===============5822851026416491652==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5822851026416491652==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung