Mandrake Linux Security Advisory : gtk+2.0 (MDKSA-2007:039)

low Nessus Plugin ID 24652

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) allows context-dependent attackers to cause a denial of service (crash) via a malformed image file. (CVE-2007-0010)

The version of libgtk+2.0 shipped with Mandriva Linux 2007 fails various portions of the lsb-test-desktop test suite, part of LSB 3.1 certification testing.

The updated packages also address the following issues :

The Home and Desktop entries in the GTK File Chooser are not always visible (#26644).

GTK+-based applications (which includes all the Mandriva Linux configuration tools, for example) crash (instead of falling back to the default theme) when an invalid icon theme is selected. (#27013)

Additional patches from GNOME CVS have been included to address the following issues from the GNOME bugzilla :

- 357132 				- fix RGBA colormap issue

- 359537,357280,359052 		- fix various printer bugs

- 357566,353736,357050,363437,379503 - fix various crashes

- 372527				- fix fileselector bug +

potential deadlock

Solution

Update the affected packages.

Plugin Details

Severity: Low

ID: 24652

File Name: mandrake_MDKSA-2007-039.nasl

Version: 1.16

Type: local

Published: 2/18/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Low

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:gtk%2b2.0, p-cpe:/a:mandriva:linux:lib64gdk_pixbuf2.0_0, p-cpe:/a:mandriva:linux:lib64gdk_pixbuf2.0_0-devel, p-cpe:/a:mandriva:linux:lib64gtk%2b-x11-2.0_0, p-cpe:/a:mandriva:linux:lib64gtk%2b2.0_0, p-cpe:/a:mandriva:linux:lib64gtk%2b2.0_0-devel, p-cpe:/a:mandriva:linux:libgdk_pixbuf2.0_0, p-cpe:/a:mandriva:linux:libgdk_pixbuf2.0_0-devel, p-cpe:/a:mandriva:linux:libgtk%2b-x11-2.0_0, p-cpe:/a:mandriva:linux:libgtk%2b2.0_0, p-cpe:/a:mandriva:linux:libgtk%2b2.0_0-devel, cpe:/o:mandriva:linux:2007

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2/7/2007

Reference Information

CVE: CVE-2007-0010

MDKSA: 2007:039