Release date:
Updated on:
Affected Systems:
RedHat Fedora 16
GNOME gdk-pixbuf <2.26.1
GNOME gdk-pixbuf
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53548
Cve id: CVE-2012-2370
GdkPixbuf is an image loading and processing library.
Multiple integer overflow vulnerabilities exist in the implementation of the read_bitmap_file_data function in the io-xbm.c of gdk-pixbuf 2.26.1 and trigger the heap buffer overflow through the negative height and width value of the XBM file, allows remote attackers to cause DoS attacks.
<* Source: Sergey Nizovtsev
Link: https://bugzilla.gnome.org/show_bug.cgi? Id = 672811
Http://git.gnome.org/browse/gdk-pixbuf/commit? Id = 4f0f991cd454d03189497f923eb40c170c22
Https://bugs.launchpad.net/ubuntu/+source/gdk-pixbuf/+bug/681150
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNOME
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnome.org/