Uočen je sigurnosni propust u radu programskog paketa Gdk-pixbuf2, distribuiranog s Fedora 15 operacijskim sustavom. Udaljeni napadač propust može iskoristiti za preveliko iskorištenje memorije koje može dovesti do DoS napada i rušenja cijelog programa.
Paket:
gdk-pixbuf 2.x
Operacijski sustavi:
Fedora 15
Kritičnost:
4.3
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-2485
Izvorni ID preporuke:
FEDORA-2011-8672
Izvor:
Fedora
Problem:
Sigurnosna ranjivost se javlja zbog pogrešnog rukovanja određenim povratnim vrijednostima u funkciji "gdk_pixbuf__gif_image_load()".
Posljedica:
Ranjivost se može iskoristiti za preveliko iskorištavanje memorije, a time i uskraćivanje usluga.
Rješenje:
Rješenje problema sigurnosti navedenog programskog paketa je korištenje dostupnih programskih zakrpa.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-8672
2011-06-24 17:36:03
--------------------------------------------------------------------------------
Name : gdk-pixbuf2
Product : Fedora 15
Version : 2.23.3
Release : 2.fc15
URL : http://www.gt.org
Summary : An image loading library
Description :
gdk-pixbuf is an image loading library that can be extended by loadable
modules for new image formats. It is used by toolkits such as GTK+ or
clutter.
--------------------------------------------------------------------------------
Update Information:
It was found that gdk-pixbuf GIF image loader gdk_pixbuf__gif_image_load()
routine did not properly handle certain return values from their subroutines. A
remote attacker could provide a specially-crafted GIF image, which once opened
in an application, linked against gdk-pixbuf would lead to gdk-pixbuf to return
partially initialized pixbuf structure, possibly having huge width and height,
leading to that particular application termination due excessive memory use.
The CVE identifier of CVE-2011-2485 has been assigned to this issue.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jun 24 2011 Matthias Clasen <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.23.3-2
- Don't return a partially initialized pixbuf structure
from the GIF loader (CVE-2011-2485)
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update gdk-pixbuf2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke