Oval Definition:oval:com.redhat.rhsa:def:20080134
Revision Date:2008-03-20Version:633
Title:RHSA-2008:0134: tcltk security update (Moderate)
Description:Tcl is a scripting language designed for embedding into other applications and for use with Tk, a widget set.

  • An input validation flaw was discovered in Tk's GIF image handling. A code-size value read from a GIF image was not properly validated before being used, leading to a buffer overflow. A specially crafted GIF file could use this to cause a crash or, potentially, execute code with the privileges of the application using the Tk graphical toolkit. (CVE-2008-0553)

  • A buffer overflow flaw was discovered in Tk's animated GIF image handling. An animated GIF containing an initial image smaller than subsequent images could cause a crash or, potentially, execute code with the privileges of the application using the Tk library. (CVE-2007-5378)

  • A flaw in the Tcl regular expression handling engine was discovered by Will Drewry. This flaw, first discovered in the Tcl regular expression engine used in the PostgreSQL database server, resulted in an infinite loop when processing certain regular expressions. (CVE-2007-4772)

    All users are advised to upgrade to these updated packages which contain backported patches which resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-4772
    CVE-2007-5378
    CVE-2008-0553
    RHSA-2008:0134
    RHSA-2008:0134-01
    RHSA-2008:0134-01
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • expect is earlier than 0:5.38.0-92.8
  • AND expect is signed with Red Hat master key
  • tk-devel is earlier than 0:8.3.5-92.8
  • AND tk-devel is signed with Red Hat master key
  • itcl is earlier than 0:3.2-92.8
  • AND itcl is signed with Red Hat master key
  • tcl is earlier than 0:8.3.5-92.8
  • AND tcl is signed with Red Hat master key
  • tk is earlier than 0:8.3.5-92.8
  • AND tk is signed with Red Hat master key
  • tclx is earlier than 0:8.3-92.8
  • AND tclx is signed with Red Hat master key
  • expect-devel is earlier than 0:5.38.0-92.8
  • AND expect-devel is signed with Red Hat master key
  • tix is earlier than 1:8.1.4-92.8
  • AND tix is signed with Red Hat master key
  • tcl-devel is earlier than 0:8.3.5-92.8
  • AND tcl-devel is signed with Red Hat master key
  • BACK