Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2004-286: gdk-pixbuf Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the gdk-pixbuf package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2004-286 (gdk-pixbuf).
The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment. The GdkPixBuf library provides image
loading facilities, the rendering of a GdkPixBuf into various formats
(drawables or GdkRGB buffers), and a cache interface.
During testing of a previously fixed flaw in Qt (CVE-2004-0691), a flaw
was discovered in the BMP image processor of gdk-pixbuf. A possible hacker could
create a carefully crafted BMP file which would cause an application
to enter an infinite loop and not respond to user input when the file
was opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2004-0753 to this issue.
During a security audit, Chris Evans discovered a stack and a heap
overflow in the XPM image decoder. A possible hacker could create a carefully crafted
XPM file which could cause an application linked with gtk2 to crash or
possibly execute arbitrary code when the file was opened by a victim.
Chris Evans also discovered an integer overflow in the ICO image
decoder. A possible hacker could create a carefully crafted ICO file which could cause
an application linked with gtk2 to crash when the file is opened by a
Solution : http://www.fedoranews.org/updates/FEDORA-2004-286.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.