Description: | Description:
The remote host is missing an update to gdk-pixbuf/gtk+2 announced via advisory MDKSA-2004:095-1.
A vulnerability was found in the gdk-pixbug bmp loader where a bad BMP image could send the bmp loader into an infinite loop (CVE-2004-0753).
Chris Evans found a heap-based overflow and a stack-based overflow in the xpm loader of gdk-pixbuf (CVE-2004-0782 and CVE-2004-0783).
Chris Evans also discovered an integer overflow in the ico loader of gdk-pixbuf (CVE-2004-0788).
All four problems have been corrected in these updated packages.
Update:
The previous package had an incorrect patch applied that would cause some problems with other programs. The updated packages have the correct patch applied.
As well, patched gtk+2 packages, which also contain gdk-pixbuf, are now provided.
Affected versions: 10.0, 9.2
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:095-1 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0753 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0788
Risk factor : High
CVSS Score: 7.5
|