LWN.net Logo

Ubuntu alert USN-216-1 (gtk+2.0, gdk-pixbuf)

From:  Martin Pitt <martin.pitt@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-216-1] GDK vulnerabilities
Date:  Wed, 16 Nov 2005 13:12:49 +0100
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com

=========================================================== Ubuntu Security Notice USN-216-1 November 16, 2005 gtk+2.0, gdk-pixbuf vulnerabilities CVE-2005-2975, CVE-2005-2976, CVE-2005-3186 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) Ubuntu 5.10 (Breezy Badger) The following packages are affected: gtk2-engines-pixbuf libgdk-pixbuf2 The problem can be corrected by upgrading the affected package to the following versions: Ubuntu 4.10: libgdk-pixbuf2: 0.22.0-7ubuntu1.2 gtk2-engines-pixbuf: 2.6.4-0ubuntu3.1 Ubuntu 5.04: libgdk-pixbuf2: 0.22.0-7ubuntu2.1 gtk2-engines-pixbuf: 2.6.4-0ubuntu3.1 Ubuntu 5.10: libgdk-pixbuf2: 0.22.0-8ubuntu0.1 gtk2-engines-pixbuf: 2.8.6-0ubuntu2.1 After a standard system upgrade you should restart your session to effect the necessary changes. Details follow: Two integer overflows have been discovered in the XPM image loader of the GDK pixbuf library. By tricking an user into opening a specially crafted XPM image with any Gnome desktop application that uses this library, this could be exploited to execute arbitrary code with the privileges of the user running the application. (CVE-2005-2976, CVE-2005-3186) Additionally, specially crafted XPM images could cause an endless loop in the image loader, which could be exploited to cause applications trying to open that image to hang. (CVE-2005-2975) Updated packages for Ubuntu 4.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 375968 809e328e7978a1a05c363744b669a40e http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 723 6c4495f57699b76148a0602927545e20 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 519266 4db0503b5a62533db68b03908b981751 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 49509 0ce4ae3ba4a43acaec0e267593c56400 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 1936 dde6d8e7ba7c47e843a5dc8c2b680499 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 14140860 b1876ebde3b85bceb576ee5e2ecfd60b Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2778618 00f15aa5dba52503adaf47cede461b2c http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 1877958 bd501df1b60309f472ad33ee74200584 amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 262178 27831fe024d2d09ac5f3c9c457ae0032 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 155374 c617a31cf7408ff7ccc6dcf544e766a1 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 8520 09e152c4a295c6b3b6e52375e0355e43 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7936 baecd3a2aca1cb678e652782da890483 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 183498 080cdd7e1cb08979fc0140a191baf418 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2184102 04a8f1b3e01bf5618f5d8b70645be6bb http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 13932 9ed21c2bb288a11e4ca2436f4757abda http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 10299800 a385ad242f16a96a1ba27b8945255856 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2841762 39311a1c6efc513741b6d38cd1b38f68 i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 258802 74c64c0bc8320c3452d63f9c4dfe4579 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 147244 70d3c463e5158902c8218806cf9bea26 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7646 46d4bf959232f67c91d79fbd65c8dcf6 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7196 d3ce271d26cc27a9e5c0a6210fcf7572 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 167628 de9143f819e8bb0dcffcee6a4db792d8 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2000838 4847eb2dd4a72f5bc34854760923d050 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 13274 b714b3281ff91c464a656a4925d0a00d http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 10067838 0c8607d981f29d1299b64595bcb99b67 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2484502 6f66278c77a34c1d3a15e1c83c41e1a2 powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 260572 e24add495a04c1c1b25c272930cbb84c http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 163110 173f3e9c62f04eaf2172f9a2ce83a4b1 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9168 2e23ba689c73ffed8e0152b21fc583ad http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9498 37a0696d1b507bb92915483283e59157 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 192398 870f2b56e70c4693d56fb8edfb0aff3c http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2118712 d8a59f2012eb87e363aa79e3170a6b6b http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 16074 c7169e71f2312165522ba44f83cdeb48 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 10329116 bac97fb5baf484e99a9a50a1ed786547 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 3084958 9425daad3786af42ab3e86fcc6cf8b33 Updated packages for Ubuntu 5.04: Source archives: http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 376111 c492f91b00c2916bf8bb2fba1361a4ff http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 723 171466244a96b3dade56b6e0c8efa1ca http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 519266 4db0503b5a62533db68b03908b981751 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 50149 53e5fdc9aaf4451b87db8e29df81040f http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 1985 a4df4df6c18f334aa4ae129eb8e8afbb http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 16354198 a3ab72c9c80384fb707b992eb8b43c13 Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2983638 8ab05d1bc68d9c1d22ee741381742639 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2317310 ee17ef17235d1d6a4ef0d54e031e123a amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 54608 dc1bb20ecdd52f4fb0c0497b1567a131 http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 262538 06ad53a8d18d71e75361d72d2a4ba840 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 155372 363d72111cf8691af67f3dfb4f53994f http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 8522 b7bb042616403a28aeb3786ae4918797 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7944 f64f19f57edd9e054a09a1e742f72b39 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 183480 16e6686cab0a7476e60efc5593647a26 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 17676230 a5873b870d4789023b3c17d76d661f6a http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2197970 1c7e872997f54018cf6102584e70e328 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 19696 53805eba8075e324953080bd2131847f http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 7618474 83fa7192d257564740c694f3d0b1b649 i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 49376 1d5c883b7ddaa60bfaf9f9953450820c http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 255970 97c1e374b68e1b54fe3d931bda5e9a69 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 147242 681b96f88d7bb61ce8012f57e2de71bf http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7644 ab947e05d78b0aeb5beb9705fd3bfc6c http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7192 2702e72f80b01417685cd09d03a4253d http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 167646 1dfb1075ad22d145c945fc5839710d79 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 17551084 07c30b56ec71a96e7c88cea0c8a50f6b http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2043574 d367d1ef37e870cdb33f2d69d35f4398 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 18054 9f9ecf765d714ba1e64ab7edfe5c6161 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 7137350 123f813938ce0a1725a167a41bcd2ddf powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 56252 c1b6e25af8dbf755c8f4a601320dee44 http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 259464 00f3744cd69651d372e5b31656a10ce7 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 163124 0fc9827cd18461e700f8b4ec497075ae http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9186 55b0581a3831617bc758cf188cd7fa4c http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9524 027786275a38c446a14bcab84c1a1fc3 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 192608 6a844ec75ed699a046db71dcae6f72af http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 28634736 4d128cb79409de36d3493eb1dcc02387 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2185946 9047f48927c90012dedb1cdc5c9171ae http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 22242 ebea993df111769c27a03bec910c566f http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 8261626 d729db63b9dc745ad81bac701ff4aa8b Updated packages for Ubuntu 5.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 375944 00715885ca7bc8de1d19c146b899a4b7 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 723 2caafab67407c8e22021f0129a515f96 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 519266 4db0503b5a62533db68b03908b981751 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 52717 02d76a955747bb6d6363c842094fbcf6 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 2109 d5cd5a823b465fa6b2691cd9bb92cb63 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 17454378 9787feb9a4ece62aec9cf1d7e676ba6d Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 3413588 f7299b417104b77813160e70f0240db0 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2378168 98b9ce5688e70cfff876505dfea8bebe amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 52452 7a14c9e5c6a273b21b893f0f5c82038a http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 270748 9d94e2017bb2d2a755bc89c55606f58a http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 157354 ec6af1a89ce275876ac8b9f1aa5fae83 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 8396 5151f8f8eb5bde4f2d8f17136fa4864f http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7620 d9db000d4335d88ddf3b3082f9e87ae1 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 183950 9b5a0c4d53b53f09d4e889f2e5c18e57 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 4236698 41432dada3e85b7e46b76399b455360a http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2272976 66b4c1d2c6c0b0e18918b23525691e39 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 23060 192f2fe3f61f6ae1a17879342491d9af http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2609212 e8c97c27e3ef6e1d7bcad87b27e70ee9 i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 46732 3e7aeb058b2d5f4baedd535c6b321d14 http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 264340 b8e7a9c45b772dfe81dd3553fa6dec40 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 147898 2bb1722dbbf96ed9dbd477e19ca172fe http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 7556 e3282c4044ea415cb3aa2532fd90a344 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 6952 4a0d002c7fbe8cadef13849879ffa2da http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 166196 d1395b65ef93c7993d8e180d08d662dd http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 3564260 3cfeb8ddc04a85495c694633e44cede0 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2052512 1d6149e8e9de36547ad5844976d132df http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 21322 04bce721f7836af237cced77095c5211 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2215654 c20c7f62665f69b20c77013b755957f8 powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/gtk... Size/MD5: 53316 10c6c00f0f13ff08a98b06af52013cc2 http://security.ubuntu.com/ubuntu/pool/universe/g/gtk+2.0... Size/MD5: 269582 13d86d36370ea066a60c7b5ab91f5630 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 165518 ff275f4dcd7234fcf18623dc7756b07a http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9214 450d72de349ce047175414e95aad4596 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 9450 f46b9f70458ea556c5ea8347cfc317d6 http://security.ubuntu.com/ubuntu/pool/main/g/gdk-pixbuf/... Size/MD5: 190138 d8d4491b44cd5e63b531c4c860e201c6 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 4190192 d62f5f56465c2a9a3cc21125c6cf6f08 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2250052 1ee48c6a95c0b7b59e1d810f8c926a86 http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 25728 887cd5903d20072297ff5480895ce40d http://security.ubuntu.com/ubuntu/pool/main/g/gtk+2.0/lib... Size/MD5: 2709362 06c909526b10fa95b56fe1bdb4fe4257 -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com http://lists.ubuntu.com/mailman/listinfo/ubuntu-security-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds