Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Contribute
Contribute
Link to Us
Linux Jobs


Top White Papers

More on LinuxToday


SOT Linux Advisory: gdk-pixbuf

Mar 12, 2004, 17:56 (0 Talkback[s])

SOT Linux Security Advisory

Subject: Updated gdk-pixbuf package for SOT Linux 2003
Advisory ID: SLSA-2004:6
Date: Thursday, March 11, 2004
Product: SOT Linux 2003


1. Problem description

The gdk-pixbuf library is a toolkit for image loading and pixel buffer manipulation that you can use in conjunction with libart. Gdk-pixbuf also provides convenience functions for progressive image loading, animation, and rendering the libart image buffer to a GdkDrawable instance.

A vulnerability in gdk-pixbuf versions before 0.20 exists that could allow a malicious BMP file to crash the Evolution mail client. The updated packages have been patched to use gdk-pixbuf 0.22.0's BMPhandling code.

2. Updated packages

SOT Linux 2003 Desktop:

i386:
ftp://ftp.sot.com/updates/2003/Desktop/i386/gdk-pixbuf-0.18.0-3.i386.rpm
ftp://ftp.sot.com/updates/2003/Desktop/i386/gdk-pixbuf-devel-0.18.0-3.i386.rpm
ftp://ftp.sot.com/updates/2003/Desktop/i386/gdk-pixbuf-gnome-0.18.0-3.i386.rpm

SRPMS:
ftp://ftp.sot.com/updates/2003/Desktop/SRPMS/gdk-pixbuf-0.18.0-3.src.rpm

SOT Linux 2003 Server:

i386:
ftp://ftp.sot.com/updates/2003/Server/i386/gdk-pixbuf-0.18.0-3.i386.rpm
ftp://ftp.sot.com/updates/2003/Server/i386/gdk-pixbuf-devel-0.18.0-3.i386.rpm
ftp://ftp.sot.com/updates/2003/Server/i386/gdk-pixbuf-gnome-0.18.0-3.i386.rpm

SRPMS:
ftp://ftp.sot.com/updates/2003/Server/SRPMS/gdk-pixbuf-0.18.0-3.src.rpm

3. Upgrading package

Before applying this update, make sure all previously released errata relevant to your system have been applied.

Use up2date to automatically upgrade the fixed packages.

If you want to upgrade manually, download the updated package from the SOT Linux FTP site (use the links above) or from one of our mirrors. The list of mirrors can be obtained at www.sot.com/en/linux

Update the package with the following command: rpm -Uvh <filename>

4. Verification

All packages are PGP signed by SOT for security.

You can verify each package with the following command: rpm --checksig <filename>

If you wish to verify the integrity of the downloaded package, run "md5sum <filename>" and compare the output with data given below.

Package Name MD5 sum


/Desktop/i386/gdk-pixbuf-gnome-0.18.0-3.i386.rpm 54bf7ba90004c8decd2b51a1ffeb12ff
/Desktop/i386/gdk-pixbuf-0.18.0-3.i386.rpm 8c7160d4a42f5c9f77ea00df9ea9232b
/Desktop/i386/gdk-pixbuf-devel-0.18.0-3.i386.rpm 5d17a9c2bafe7424ad6182acf0916e17
/Desktop/SRPMS/gdk-pixbuf-0.18.0-3.src.rpm 63641f85d47f7138f4df667b2308211f
/Server/i386/gdk-pixbuf-gnome-0.18.0-3.i386.rpm 54bf7ba90004c8decd2b51a1ffeb12ff
/Server/i386/gdk-pixbuf-0.18.0-3.i386.rpm 8c7160d4a42f5c9f77ea00df9ea9232b
/Server/i386/gdk-pixbuf-devel-0.18.0-3.i386.rpm 5d17a9c2bafe7424ad6182acf0916e17
/Server/SRPMS/gdk-pixbuf-0.18.0-3.src.rpm 63641f85d47f7138f4df667b2308211f

5. References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0111

Copyright(c) 2001-2003 SOT