| From: |
| Pat Riehecky <riehecky@fnal.gov> |
| To: |
| "SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV"
<SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV> |
| Subject: |
| Security ERRATA Moderate: gegl on SL6.x i386/x86_64 |
| Date: |
| Mon, 12 Nov 2012 16:02:27 -0600 |
| Message-ID: |
| <50A171F3.6040709@fnal.gov> |
| Archive-link: |
| Article, Thread
|
Synopsis: Moderate: gegl security update
Issue Date: 2012-11-12
CVE Numbers: CVE-2012-4433
--
An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the gegl utility processed .ppm (Portable Pixel Map) image
files. An attacker could create a specially-crafted .ppm file that, when
opened in gegl, would cause gegl to crash or, potentially, execute
arbitrary code. (CVE-2012-4433)
--
SL6
x86_64
gegl-0.1.2-4.el6_3.x86_64.rpm
gegl-0.1.2-4.el6_3.i686.rpm
gegl-devel-0.1.2-4.el6_3.i686.rpm
gegl-devel-0.1.2-4.el6_3.x86_64.rpm
i386
gegl-0.1.2-4.el6_3.i686.rpm
gegl-devel-0.1.2-4.el6_3.i686.rpm
- Scientific Linux Development Team
(
Log in to post comments)