Mandrake Linux Security Advisory : gtk+2.0 (MDKSA-2007:039)

Low Nessus Plugin ID 24652


The remote Mandrake Linux host is missing one or more security updates.


The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) allows context-dependent attackers to cause a denial of service (crash) via a malformed image file. (CVE-2007-0010)

The version of libgtk+2.0 shipped with Mandriva Linux 2007 fails various portions of the lsb-test-desktop test suite, part of LSB 3.1 certification testing.

The updated packages also address the following issues :

The Home and Desktop entries in the GTK File Chooser are not always visible (#26644).

GTK+-based applications (which includes all the Mandriva Linux configuration tools, for example) crash (instead of falling back to the default theme) when an invalid icon theme is selected. (#27013)

Additional patches from GNOME CVS have been included to address the following issues from the GNOME bugzilla :

- 357132 				- fix RGBA colormap issue

- 359537,357280,359052 		- fix various printer bugs

- 357566,353736,357050,363437,379503 - fix various crashes

- 372527				- fix fileselector bug +

potential deadlock


Update the affected packages.

Plugin Details

Severity: Low

ID: 24652

File Name: mandrake_MDKSA-2007-039.nasl

Version: $Revision: 1.13 $

Type: local

Published: 2007/02/18

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: Low


Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:gtk+2.0, p-cpe:/a:mandriva:linux:lib64gdk_pixbuf2.0_0, p-cpe:/a:mandriva:linux:lib64gdk_pixbuf2.0_0-devel, p-cpe:/a:mandriva:linux:lib64gtk+-x11-2.0_0, p-cpe:/a:mandriva:linux:lib64gtk+2.0_0, p-cpe:/a:mandriva:linux:lib64gtk+2.0_0-devel, p-cpe:/a:mandriva:linux:libgdk_pixbuf2.0_0, p-cpe:/a:mandriva:linux:libgdk_pixbuf2.0_0-devel, p-cpe:/a:mandriva:linux:libgtk+-x11-2.0_0, p-cpe:/a:mandriva:linux:libgtk+2.0_0, p-cpe:/a:mandriva:linux:libgtk+2.0_0-devel, cpe:/o:mandriva:linux:2007

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2007/02/07

Reference Information

CVE: CVE-2007-0010

MDKSA: 2007:039