[Saidi Net News] a high-risk vulnerability related to images appeared in Linux, making Linux vendors busy patching.
This vulnerability occurs in gdkpixbuf, which can cause DoS attacks or provide remote system access.
Vulnerabilities can be divided into several types. One of them is a variant of the previously discovered QT vulnerability, which exists in bitmap images and can run in an endless loop. The second is "pixbuf_create_from_xpm ()", which occurs when the XPM image is decoded. The third is the boundary error of the "xpm_extract_color ()" function, which occurs when the XPM image is decoded and can also cause buffer overflow. The last one is the input validation error during ICO image decoding, which can cause integer overflow.
According to the secunia consulting report, there is no official version of gdkpixbuf. However, Red Hat, Debian, fedora, and MandrakeSoft have released their respective patches and upgraded versions.
From: SCID