Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55893
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-216-1 (gdk-pixbuf)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to gdk-pixbuf
announced via advisory USN-216-1.

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected: gtk2-engines-pixbuf libgdk-pixbuf2

Two integer overflows have been discovered in the XPM image loader of
the GDK pixbuf library. By tricking an user into opening a specially
crafted XPM image with any Gnome desktop application that uses this
library, this could be exploited to execute arbitrary code with the
privileges of the user running the application.
(CVE-2005-2976, CVE-2005-3186)

Additionally, specially crafted XPM images could cause an endless loop
in the image loader, which could be exploited to cause applications
trying to open that image to hang. (CVE-2005-2975)

Solution:
The problem can be corrected by upgrading the affected package to
the following versions:

Ubuntu 4.10:
libgdk-pixbuf2: 0.22.0-7ubuntu1.2
gtk2-engines-pixbuf: 2.6.4-0ubuntu3.1

Ubuntu 5.04:
libgdk-pixbuf2: 0.22.0-7ubuntu2.1
gtk2-engines-pixbuf: 2.6.4-0ubuntu3.1

Ubuntu 5.10:
libgdk-pixbuf2: 0.22.0-8ubuntu0.1
gtk2-engines-pixbuf: 2.8.6-0ubuntu2.1

After a standard system upgrade you should restart your session to
effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-216-1

Risk factor : High

CVSS Score:
7.8

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2975
1015216
http://securitytracker.com/id?1015216
15429
http://www.securityfocus.com/bid/15429
17522
http://secunia.com/advisories/17522
17538
http://secunia.com/advisories/17538
17562
http://secunia.com/advisories/17562
17588
http://secunia.com/advisories/17588
17591
http://secunia.com/advisories/17591
17592
http://secunia.com/advisories/17592
17594
http://secunia.com/advisories/17594
17615
http://secunia.com/advisories/17615
17657
http://secunia.com/advisories/17657
17710
http://secunia.com/advisories/17710
17770
http://secunia.com/advisories/17770
17791
http://secunia.com/advisories/17791
ADV-2005-2433
http://www.vupen.com/english/advisories/2005/2433
DSA-911
http://www.debian.org/security/2005/dsa-911
DSA-913
http://www.debian.org/security/2005/dsa-913
FLSA:173274
http://www.securityfocus.com/archive/1/428052/100/0/threaded
GLSA-200511-14
http://www.gentoo.org/security/en/glsa/glsa-200511-14.xml
MDKSA-2005:214
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214
RHSA-2005:810
http://www.redhat.com/support/errata/RHSA-2005-810.html
RHSA-2005:811
http://www.redhat.com/support/errata/RHSA-2005-811.html
SUSE-SA:2005:065
http://www.novell.com/linux/security/advisories/2005_65_gtk2.html
USN-216-1
http://www.ubuntu.com/usn/usn-216-1
http://support.avaya.com/elmodocs2/security/ASA-2005-229.pdf
oval:org.mitre.oval:def:9697
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9697
Common Vulnerability Exposure (CVE) ID: CVE-2005-2976
15428
http://www.securityfocus.com/bid/15428
oval:org.mitre.oval:def:11370
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11370
Common Vulnerability Exposure (CVE) ID: CVE-2005-3186
BugTraq ID: 15435
http://www.securityfocus.com/bid/15435
Debian Security Information: DSA-911 (Google Search)
Debian Security Information: DSA-913 (Google Search)
http://www.idefense.com/application/poi/display?id=339&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9503
SCO Security Bulletin: SCOSA-2006.8
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.8/SCOSA-2006.8.txt
http://secunia.com/advisories/18509
http://securityreason.com/securityalert/188
SuSE Security Announcement: SUSE-SA:2005:065 (Google Search)
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.