PACKAGE : gtk+
SUMMARY : Fixes for image loading vulnerabilities
DATE : 2004-10-18 14:01:00
ID : CLA-2004:875
RELEVANT RELEASES : 9, 10
DESCRIPTION
The gdk-pixbuf[1] library is a replacement for imlib with many
improvements.
A vulnerability found in the gdk-pixbuf bmp loader could allow a
specially crafted BMP image to hang applications in an infinite
loop (CAN-2004-0753[2]).
Chris Evans[3] found a heap-based overflow and a stack-based
overflow on gdk-pixbuf's xpm loader (CAN-2004-0782[4] and
CAN-2004-0783[5]).
He also discovered an integer overflow in the ico loader of
gdk-pixbuf (CAN-2004-0788[6]).
SOLUTION
It is recommended that all gdk-pixbuf and/or gtk+2 users upgrade
their packages.
IMPORTANT: all applications linked against gdk-pixbuf or gtk+2
must be restarted after the upgrade in order to close the
vulnerabilities.