Oval Definition:oval:com.redhat.rhsa:def:20050810
Revision Date:2005-11-15Version:502
Title:RHSA-2005:810: gdk-pixbuf security update (Important)
Description:The gdk-pixbuf package contains an image loading library used with the GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes XPM images. An attacker could create a carefully crafted XPM file in such a way that it could cause an application linked with gdk-pixbuf to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an integer overflow bug in the way gdk-pixbuf processes XPM images. An attacker could create a carefully crafted XPM file in such a way that it could cause an application linked with gdk-pixbuf to execute arbitrary code or crash when the file was opened by a victim. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-2976 to this issue.

Ludwig Nussel also discovered an infinite-loop denial of service bug in the way gdk-pixbuf processes XPM images. An attacker could create a carefully crafted XPM file in such a way that it could cause an application linked with gdk-pixbuf to stop responding when the file was opened by a victim. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-2975 to this issue.

Users of gdk-pixbuf are advised to upgrade to these updated packages, which contain backported patches and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-2975
CVE-2005-2976
CVE-2005-3186
RHSA-2005:810-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3
  • AND gdk-pixbuf-gnome is signed with Red Hat master key
  • gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3
  • AND gdk-pixbuf-devel is signed with Red Hat master key
  • gdk-pixbuf is earlier than 1:0.22.0-13.el3.3
  • AND gdk-pixbuf is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3
  • AND gdk-pixbuf-devel is signed with Red Hat master key
  • gdk-pixbuf is earlier than 1:0.22.0-17.el4.3
  • AND gdk-pixbuf is signed with Red Hat master key
  • BACK