LWN.net Logo

Problem loading untrusted images in imlib

Package(s):imlib CVE #(s):CAN-2002-0167 CAN-2002-0168
Created:May 21, 2002 Updated:June 6, 2002
Description: Versions of imlib prior to 1.9.13 used the NetPBM package in ways which "make it possible for attackers to create image files such that when loaded via software which uses Imlib, could crash the program or potentially allow arbitrary code to be executed." (First LWN report: March 28).
Alerts:
Yellow Dog YDU-20020522-3 2002-05-22
SuSE SuSE-SA:2002:015 2002-05-07
Red Hat RHSA-2002:048-14 2002-05-16
Red Hat RHSA-2002:048-06 2002-03-20
Mandrake MDKSA-2002:029 2002-04-25
Eridani ERISA-2002:015 2002-05-18
Eridani ERISA-2002:011 2002-03-27
Conectiva CLA-2002:481 2002-05-08
Conectiva CLA-2002:470 2002-03-28
SCO Group CSSA-2002-019.0 2002-04-29

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds