Security Advisory gdk-pixbuf security update

Advisory: RHSA-2004:103-05
Type: Security Advisory
Severity: Important
Issued on: 2004-03-10
Last updated on: 2004-03-10
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0111

Details

Updated gdk-pixbuf packages that fix a crash are now available.

The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

Thomas Kristensen discovered a bitmap file that would cause versions of
gdk-pixbuf prior to 0.20 to crash. To exploit this flaw, an attacker would
need to get a victim to open a carefully-crafted BMP file in an application
that used gdk-pixbuf. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0111 to this issue.

Users are advised to upgrade to these updated packages containing
gdk-pixbuf version 0.22, which is not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL Certificate
Errors, you need to install a version of the up2date client with an updated
certificate. The latest version of up2date is available from the Red Hat
FTP site and may also be downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
gdk-pixbuf-0.22.0-6.0.3.src.rpm
File outdated by:  RHSA-2005:810
    128970a02d0b6b3b6dd753e677fa9db8
 
IA-32:
gdk-pixbuf-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    084ca13b2aa023e61d8acb6c637a9fdd
gdk-pixbuf-devel-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    5dc773beabca6a1dcc5fe2e08989514c
gdk-pixbuf-gnome-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    87701753099582e758e51e811f878ecc
 
IA-64:
gdk-pixbuf-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    0282b12c24d29dbd107f60309fc26c95
gdk-pixbuf-devel-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    c7e702ed2b2868d67e7e2a6e299ca0f9
gdk-pixbuf-gnome-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    229cd0ae2acc0cde6289eec8a7f352c7
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
gdk-pixbuf-0.22.0-6.1.1.src.rpm
File outdated by:  RHSA-2005:810
    a49877536890e2e1cd1e55ff600ae263
 
IA-32:
gdk-pixbuf-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    fa03a5b2b441bae8338a17f884d0ad5d
gdk-pixbuf-devel-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    9b1e815c0dc937c03c3095c9299b99e0
gdk-pixbuf-gnome-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    92a8e1f2a6743dc1e4a3abac6db25c58
 
IA-64:
gdk-pixbuf-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    224507a5e24f6072b248371a266af5e9
gdk-pixbuf-devel-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    47370691824a745e336dd00ec4a4fd4f
gdk-pixbuf-gnome-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    3f12660f4158b339571f2adeeffb68d1
 
PPC:
gdk-pixbuf-0.22.0-6.1.1.ppc.rpm
File outdated by:  RHSA-2005:810
    e0e7a3e905768769e2a8928f68996748
gdk-pixbuf-devel-0.22.0-6.1.1.ppc.rpm
File outdated by:  RHSA-2005:810
    72610308a9609c69ec8bd880c2baaf0a
gdk-pixbuf-gnome-0.22.0-6.1.1.ppc.rpm
File outdated by:  RHSA-2005:810
    a4f425224ffd6a79a433364e2ba5b48a
 
s390:
gdk-pixbuf-0.22.0-6.1.1.s390.rpm
File outdated by:  RHSA-2005:810
    ade26a54f2f46b023375208faabe330d
gdk-pixbuf-devel-0.22.0-6.1.1.s390.rpm
File outdated by:  RHSA-2005:810
    8d5831f05f263aa2ad8351a073acb4e5
gdk-pixbuf-gnome-0.22.0-6.1.1.s390.rpm
File outdated by:  RHSA-2005:810
    34d8e15b8ed3ebc40ecafef2d8d31495
 
s390x:
gdk-pixbuf-0.22.0-6.1.1.s390x.rpm
File outdated by:  RHSA-2005:810
    9447f1d9aa3085787fca10483448a08b
gdk-pixbuf-devel-0.22.0-6.1.1.s390x.rpm
File outdated by:  RHSA-2005:810
    bd64e3669337df7f5c25447cd47804a4
gdk-pixbuf-gnome-0.22.0-6.1.1.s390x.rpm
File outdated by:  RHSA-2005:810
    78d6d4f9a4338b909f3e44b5f49e9127
 
x86_64:
gdk-pixbuf-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    2ba13b1af3f8eec7ec8320be10310073
gdk-pixbuf-devel-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    292efbac89a92e2caab6d57e85568877
gdk-pixbuf-gnome-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    847dad18037832f5642a9b2ef7a139ab
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
gdk-pixbuf-0.22.0-6.0.3.src.rpm
File outdated by:  RHSA-2005:810
    128970a02d0b6b3b6dd753e677fa9db8
 
IA-32:
gdk-pixbuf-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    084ca13b2aa023e61d8acb6c637a9fdd
gdk-pixbuf-devel-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    5dc773beabca6a1dcc5fe2e08989514c
gdk-pixbuf-gnome-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    87701753099582e758e51e811f878ecc
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
gdk-pixbuf-0.22.0-6.1.1.src.rpm
File outdated by:  RHSA-2005:810
    a49877536890e2e1cd1e55ff600ae263
 
IA-32:
gdk-pixbuf-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    fa03a5b2b441bae8338a17f884d0ad5d
gdk-pixbuf-devel-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    9b1e815c0dc937c03c3095c9299b99e0
gdk-pixbuf-gnome-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    92a8e1f2a6743dc1e4a3abac6db25c58
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
gdk-pixbuf-0.22.0-6.0.3.src.rpm
File outdated by:  RHSA-2005:810
    128970a02d0b6b3b6dd753e677fa9db8
 
IA-32:
gdk-pixbuf-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    084ca13b2aa023e61d8acb6c637a9fdd
gdk-pixbuf-devel-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    5dc773beabca6a1dcc5fe2e08989514c
gdk-pixbuf-gnome-0.22.0-6.0.3.i386.rpm
File outdated by:  RHSA-2005:810
    87701753099582e758e51e811f878ecc
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
gdk-pixbuf-0.22.0-6.1.1.src.rpm
File outdated by:  RHSA-2005:810
    a49877536890e2e1cd1e55ff600ae263
 
IA-32:
gdk-pixbuf-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    fa03a5b2b441bae8338a17f884d0ad5d
gdk-pixbuf-devel-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    9b1e815c0dc937c03c3095c9299b99e0
gdk-pixbuf-gnome-0.22.0-6.1.1.i386.rpm
File outdated by:  RHSA-2005:810
    92a8e1f2a6743dc1e4a3abac6db25c58
 
IA-64:
gdk-pixbuf-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    224507a5e24f6072b248371a266af5e9
gdk-pixbuf-devel-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    47370691824a745e336dd00ec4a4fd4f
gdk-pixbuf-gnome-0.22.0-6.1.1.ia64.rpm
File outdated by:  RHSA-2005:810
    3f12660f4158b339571f2adeeffb68d1
 
x86_64:
gdk-pixbuf-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    2ba13b1af3f8eec7ec8320be10310073
gdk-pixbuf-devel-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    292efbac89a92e2caab6d57e85568877
gdk-pixbuf-gnome-0.22.0-6.1.1.x86_64.rpm
File outdated by:  RHSA-2005:810
    847dad18037832f5642a9b2ef7a139ab
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
gdk-pixbuf-0.22.0-6.0.3.src.rpm
File outdated by:  RHSA-2005:810
    128970a02d0b6b3b6dd753e677fa9db8
 
IA-64:
gdk-pixbuf-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    0282b12c24d29dbd107f60309fc26c95
gdk-pixbuf-devel-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    c7e702ed2b2868d67e7e2a6e299ca0f9
gdk-pixbuf-gnome-0.22.0-6.0.3.ia64.rpm
File outdated by:  RHSA-2005:810
    229cd0ae2acc0cde6289eec8a7f352c7
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

116918 - CAN-2004-0111 gdk-pixbuf can crash with malicious BMP file


References


Keywords

DoS


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/