GLSA-200511-14 : GTK+ 2, GdkPixbuf: Multiple XPM decoding vulnerabilities
High Nessus Plugin ID 20235
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200511-14 (GTK+ 2, GdkPixbuf: Multiple XPM decoding vulnerabilities)
iDEFENSE reported a possible heap overflow in the XPM loader (CVE-2005-3186). Upon further inspection, Ludwig Nussel discovered two additional issues in the XPM processing functions : an integer overflow (CVE-2005-2976) that affects only gdk-pixbuf, and an infinite loop (CVE-2005-2975).
Using a specially crafted XPM image an attacker could cause an affected application to enter an infinite loop or trigger the overflows, potentially allowing the execution of arbitrary code.
There is no known workaround at this time.
SolutionAll GTK+ 2 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose x11-libs/gtk+ All GdkPixbuf users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=media-libs/gdk-pixbuf-0.22.0-r5'