Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55944
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-913-1)
Summary:The remote host is missing an update for the Debian 'gdk-pixbuf' package(s) announced via the DSA-913-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'gdk-pixbuf' package(s) announced via the DSA-913-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been found in gdk-pixbuf, the Gtk+ GdkPixBuf XPM image rendering library. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2005-2975

Ludwig Nussel discovered an infinite loop when processing XPM images that allows an attacker to cause a denial of service via a specially crafted XPM file.

CVE-2005-2976

Ludwig Nussel discovered an integer overflow in the way XPM images are processed that could lead to the execution of arbitrary code or crash the application via a specially crafted XPM file.

CVE-2005-3186

'infamous41md' discovered an integer in the XPM processing routine that can be used to execute arbitrary code via a traditional heap overflow.

The following matrix explains which versions fix these problems:



old stable (woody)

stable (sarge)

unstable (sid)

gdk-pixbuf

0.17.0-2woody3

0.22.0-8.1

0.22.0-11

gtk+2.0

2.0.2-5woody3

2.6.4-3.1

2.6.10-2

We recommend that you upgrade your gdk-pixbuf packages.

Affected Software/OS:
'gdk-pixbuf' package(s) on Debian 3.0, Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2975
1015216
http://securitytracker.com/id?1015216
15429
http://www.securityfocus.com/bid/15429
17522
http://secunia.com/advisories/17522
17538
http://secunia.com/advisories/17538
17562
http://secunia.com/advisories/17562
17588
http://secunia.com/advisories/17588
17591
http://secunia.com/advisories/17591
17592
http://secunia.com/advisories/17592
17594
http://secunia.com/advisories/17594
17615
http://secunia.com/advisories/17615
17657
http://secunia.com/advisories/17657
17710
http://secunia.com/advisories/17710
17770
http://secunia.com/advisories/17770
17791
http://secunia.com/advisories/17791
ADV-2005-2433
http://www.vupen.com/english/advisories/2005/2433
DSA-911
http://www.debian.org/security/2005/dsa-911
DSA-913
http://www.debian.org/security/2005/dsa-913
FLSA:173274
http://www.securityfocus.com/archive/1/428052/100/0/threaded
GLSA-200511-14
http://www.gentoo.org/security/en/glsa/glsa-200511-14.xml
MDKSA-2005:214
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214
RHSA-2005:810
http://www.redhat.com/support/errata/RHSA-2005-810.html
RHSA-2005:811
http://www.redhat.com/support/errata/RHSA-2005-811.html
SUSE-SA:2005:065
http://www.novell.com/linux/security/advisories/2005_65_gtk2.html
USN-216-1
http://www.ubuntu.com/usn/usn-216-1
http://support.avaya.com/elmodocs2/security/ASA-2005-229.pdf
oval:org.mitre.oval:def:9697
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9697
Common Vulnerability Exposure (CVE) ID: CVE-2005-2976
15428
http://www.securityfocus.com/bid/15428
oval:org.mitre.oval:def:11370
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11370
Common Vulnerability Exposure (CVE) ID: CVE-2005-3186
BugTraq ID: 15435
http://www.securityfocus.com/bid/15435
Debian Security Information: DSA-911 (Google Search)
Debian Security Information: DSA-913 (Google Search)
http://www.idefense.com/application/poi/display?id=339&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9503
SCO Security Bulletin: SCOSA-2006.8
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.8/SCOSA-2006.8.txt
http://secunia.com/advisories/18509
http://securityreason.com/securityalert/188
SuSE Security Announcement: SUSE-SA:2005:065 (Google Search)
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.