|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200409-28] GTK+ 2, gdk-pixbuf: Multiple image decoding vulnerabilities Vulnerability Assessment Details
|
[GLSA-200409-28] GTK+ 2, gdk-pixbuf: Multiple image decoding vulnerabilities |
||
|
GTK+ 2, gdk-pixbuf: Multiple image decoding vulnerabilities Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200409-28 (GTK+ 2, gdk-pixbuf: Multiple image decoding vulnerabilities) A vulnerability has been discovered in the BMP image preprocessor (CVE-2004-0753). Furthermore, Chris Evans found a possible integer overflow in the pixbuf_create_from_xpm() function, resulting in a heap overflow (CVE-2004-0782). He also found a potential stack-based buffer overflow in the xpm_extract_color() function (CVE-2004-0783). A possible integer overflow has also been found in the ICO decoder. Impact With a specially crafted BMP image a possible hacker could cause an affected application to enter an infinite loop when that image is being processed. Also, by making use of specially crafted XPM or ICO images a possible hacker could trigger the overflows, which potentially permits the execution of arbitrary code. Workaround There is no known workaround at this time. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0753 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0788 http://bugzilla.gnome.org/show_bug.cgi?id=150601 Solution: All GTK+ 2 users should upgrade to the latest version: # emerge sync # emerge -pv ">=x11-libs/gtk+-2.4.9-r1" # emerge ">=x11-libs/gtk+-2.4.9-r1" All GdkPixbuf users should upgrade to the latest version: # emerge sync # emerge -pv ">=media-libs/gdk-pixbuf-0.22.0-r3" # emerge ">=media-libs/gdk-pixbuf-0.22.0-r3" Network Security Threat Level: Medium Networks Security ID: Vulnerability Assessment Copyright: (C) 2005 Michel Arboi |
||
|
Cables, Connectors |

vintage pentium 3 pc turns on no display no post
$150.00
Vintage Computer Keyboard Northgate OMNIKEY Ultra
$120.00
Lot of 2 Vintage Plextor PX-43CS SCSI CD-ROM Caddy Drives + 4 Caddies Used
$55.99
Vintage Hewlett Packard HP 13181-60074 Circuit Card Assembly / Interface Board.
$135.37
MicroProse Falcon 4.0 PC Flight Sim Big Box Manuals Korean Map CD Lot Vintage
$60.00
Vintage Military Avionics PCB AlliedSignal 1750A CPU Ceramic Aerospace Board
$299.95
Original Vintage Old Style STANDARD Black CD Jewel Case (Heavy Duty) 90g Lot
$316.95
Vintage Military Avionics PCB Philips Ceramic ASIC Gold Lid Aerospace Computer
$99.95
VINTAGE COLLECTIBLE Comp USA Maxtor 20 GB 3.5 Inch EIDE Hard Drive NEW SEALED
$500.00
Vintage Hewlett-Packard HP-25 Applications Programs 1975 Manual 00025-90011
$29.50
|
||
|
No Discussions have been posted on this vulnerability. |