EulerOS Virtualization 3.0.1.0 : gdk-pixbuf (EulerOS-SA-2019-1438)

Medium Nessus Plugin ID 124941

Synopsis

The remote EulerOS Virtualization host is missing multiple security updates.

Description

According to the versions of the gdk-pixbuf package installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities :

- An integer overflow, leading to a heap-based buffer overflow, was found in the way gdk-pixbuf, an image loading library for GNOME, scaled certain bitmap format images. An attacker could use a specially crafted BMP image file that, when processed by an application compiled against the gdk-pixbuf library, would cause that application to crash or execute arbitrary code with the permissions of the user running the application.(CVE-2015-4491)

- Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution(CVE-2017-1000422)

Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected gdk-pixbuf packages.

See Also

http://www.nessus.org/u?6bb93c05

Plugin Details

Severity: Medium

ID: 124941

File Name: EulerOS_SA-2019-1438.nasl

Version: 1.2

Type: local

Published: 2019/05/14

Updated: 2019/05/31

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:huawei:euleros:gdk-pixbuf2, cpe:/o:huawei:euleros:uvp:3.0.1.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/uvp_version

Patch Publication Date: 2019/05/07

Reference Information

CVE: CVE-2015-4491, CVE-2017-1000422