[UCI-Linux] [SECURITY] Fedora Core 4 Update: gtk2-2.6.10-2.fc4.4

Mike Iglesias iglesias at draco.acs.uci.edu
Tue Nov 15 09:54:43 PST 2005


From: "Matthias Clasen" <mclasen at redhat.com>
To: fedora-announce-list at redhat.com
Date: Tue, 15 Nov 2005 12:41:49 -0500
Subject: [SECURITY] Fedora Core 4 Update: gtk2-2.6.10-2.fc4.4

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-1088
2005-11-15
---------------------------------------------------------------------

Product     : Fedora Core 4
Name        : gtk2
Version     : 2.6.10                      
Release     : 2.fc4.4                  
Summary     : The GIMP ToolKit (GTK+), a library for creating GUIs for X.
Description :
GTK+ is a multi-platform toolkit for creating graphical user
interfaces. Offering a complete set of widgets, GTK+ is suitable for
projects ranging from small one-off tools to complete application
suites.

---------------------------------------------------------------------
Update Information:

The gtk2 package contains the GIMP ToolKit (GTK+), a library
for creating graphical user interfaces for the X Window System.

A bug was found in the way gtk2 processes XPM images. An
attacker could create a carefully crafted XPM file in such a
way that it could cause an application linked with gtk2 to
execute arbitrary code when the file was opened by a victim.
The Common Vulnerabilities and Exposures project has
assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an infinite-loop denial of service
bug in the way gtk2 processes XPM images. An attacker could
create a carefully crafted XPM file in such a way that it
could cause an application linked with gtk2 to stop
responding when the file was opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the name
CVE-2005-2975 to this issue.
 
Users of gtk2 are advised to upgrade to these updated
packages, which contain backported patches and are not
vulnerable to these issues.
---------------------------------------------------------------------
* Mon Oct 31 2005 Matthias Clasen <mclasen at redhat.com> - 2.6.10-2.fc4.4
- Prevent an infinite loop in the xpm loader (#171905, CVE-2005-2975)

* Wed Oct 19 2005 Matthias Clasen <mclasen at redhat.com> - 2.6.10-2.fc4.2
- Prevent an integer overflow in the xpm loader (#171075, CAN-2005-3186)


---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

8b6c8d169a2077aec57fb1551e6b032d  SRPMS/gtk2-2.6.10-2.fc4.4.src.rpm
5a1ab1b673c5a2efbdd75e23ad206945  ppc/gtk2-2.6.10-2.fc4.4.ppc.rpm
7880fe183673db71572a166571e5a91d  ppc/gtk2-devel-2.6.10-2.fc4.4.ppc.rpm
52958efbd0796646ad0c1ca43a086009  ppc/debug/gtk2-debuginfo-2.6.10-2.fc4.4.ppc.rpm
ef8f41011dc23c3c1432ac81b6965632  ppc/gtk2-2.6.10-2.fc4.4.ppc64.rpm
b1e55459ebf53ad98c7c991c4a771539  x86_64/gtk2-2.6.10-2.fc4.4.x86_64.rpm
eb387f58aabad431bc6ac4e9c377c81f  x86_64/gtk2-devel-2.6.10-2.fc4.4.x86_64.rpm
ed1e986aaca3a7d6fe01efaa5227de1e  x86_64/debug/gtk2-debuginfo-2.6.10-2.fc4.4.x86_64.rpm
06c4edc69cd8cefc88e0745c9cbad651  x86_64/gtk2-2.6.10-2.fc4.4.i386.rpm
06c4edc69cd8cefc88e0745c9cbad651  i386/gtk2-2.6.10-2.fc4.4.i386.rpm
e9f0a994835b3666c1b85f38121e3251  i386/gtk2-devel-2.6.10-2.fc4.4.i386.rpm
d5ab5b36abd4882a3f0d6081179959d3  i386/debug/gtk2-debuginfo-2.6.10-2.fc4.4.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------

-- 
fedora-announce-list mailing list
fedora-announce-list at redhat.com
https://www.redhat.com/mailman/listinfo/fedora-announce-list


More information about the UCI-Linux mailing list