Lucene search

K
gentooGentoo FoundationGLSA-200511-14
HistoryNov 16, 2005 - 12:00 a.m.

GTK+ 2, GdkPixbuf: Multiple XPM decoding vulnerabilities

2005-11-1600:00:00
Gentoo Foundation
security.gentoo.org
17

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.021

Percentile

89.2%

Background

GTK+ (the GIMP Toolkit) is a toolkit for creating graphical user interfaces. The GdkPixbuf library provides facilities for image handling. It is available as a standalone library and also packaged with GTK+ 2.

Description

iDEFENSE reported a possible heap overflow in the XPM loader (CVE-2005-3186). Upon further inspection, Ludwig Nussel discovered two additional issues in the XPM processing functions : an integer overflow (CVE-2005-2976) that affects only gdk-pixbuf, and an infinite loop (CVE-2005-2975).

Impact

Using a specially crafted XPM image an attacker could cause an affected application to enter an infinite loop or trigger the overflows, potentially allowing the execution of arbitrary code.

Workaround

There is no known workaround at this time.

Resolution

All GTK+ 2 users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose x11-libs/gtk+

All GdkPixbuf users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-libs/gdk-pixbuf-0.22.0-r5"
OSVersionArchitecturePackageVersionFilename
Gentooanyallx11-libs/gtk+< 2.8.6-r1UNKNOWN
Gentooanyallmedia-libs/gdk-pixbuf< 0.22.0-r5UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.021

Percentile

89.2%