Login
Newsletter
Werbung

Sicherheit: Denial of Service in gdk-pixbuf2
Aktuelle Meldungen Distributionen
Name: Denial of Service in gdk-pixbuf2
ID: FEDORA-2011-8667
Distribution: Fedora
Plattformen: Fedora 14
Datum: Mi, 17. August 2011, 08:58
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2485
Applikationen: GTK

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2011-8667
2011-06-24 17:35:52
-------------------------------------------------------------------------------
-

Name : gdk-pixbuf2
Product : Fedora 14
Version : 2.22.0
Release : 2.fc14
URL : http://www.gt.org
Summary : An image loading library
Description :
gdk-pixbuf is an image loading library that can be extended by loadable
modules for new image formats. It is used by toolkits such as GTK+ or
clutter.

-------------------------------------------------------------------------------
-
Update Information:

It was found that gdk-pixbuf GIF image loader gdk_pixbuf__gif_image_load()
routine did not properly handle certain return values from their subroutines. A remote attacker could provide a specially-crafted GIF image, which once opened in an application, linked against gdk-pixbuf would lead to gdk-pixbuf
to return partially initialized pixbuf structure, possibly having huge width
and height, leading to that particular application termination due excessive memory use.

The CVE identifier of CVE-2011-2485 has been assigned to this issue.
-------------------------------------------------------------------------------
-
ChangeLog:

* Fri Jun 24 2011 Matthias Clasen <mclasen@redhat.com> 2.22.0-2
- Don't return a partially initialized pixbuf structure
from the GIF loader (CVE-2011-2485)
* Wed Sep 29 2010 jkeating - 2.22.0-1.1
- Rebuilt for gcc bug 634757
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update gdk-pixbuf2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung