Oval Definition:oval:com.redhat.rhsa:def:20080131
Revision Date:2008-02-28Version:635
Title:RHSA-2008:0131: netpbm security update (Moderate)
Description:The netpbm package contains a library of functions for editing and converting between various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps) and others. The package includes no interactive tools and is primarily used by other programs (eg CGI scripts that manage web-site images).

  • An input validation flaw was discovered in the GIF-to-PNM converter (giftopnm) shipped with the netpbm package. An attacker could create a carefully crafted GIF file which could cause giftopnm to crash or possibly execute arbitrary code as the user running giftopnm. (CVE-2008-0554)

    All users are advised to upgrade to these updated packages which contain a backported patch which resolves this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-0554
    RHSA-2008:0131
    RHSA-2008:0131-01
    RHSA-2008:0131-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • netpbm-devel is earlier than 0:9.24-11.30.5
  • AND netpbm-devel is signed with Red Hat master key
  • netpbm-progs is earlier than 0:9.24-11.30.5
  • AND netpbm-progs is signed with Red Hat master key
  • netpbm is earlier than 0:9.24-11.30.5
  • AND netpbm is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • netpbm-progs is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm-progs is signed with Red Hat master key
  • netpbm is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm is signed with Red Hat master key
  • netpbm-devel is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm-devel is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • netpbm is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm is signed with Red Hat redhatrelease2 key
  • netpbm-devel is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm-devel is signed with Red Hat redhatrelease2 key
  • netpbm-progs is earlier than 0:10.25-2.EL4.6.el4_6.1
  • AND netpbm-progs is signed with Red Hat redhatrelease2 key
  • BACK