GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
BID:22209
Info
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
| Bugtraq ID: | 22209 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-0010 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2007 12:00AM |
| Updated: | May 17 2007 07:28PM |
| Credit: | Lubomir Kundrak discovered this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 S.u.S.E. openSUSE 10.2 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Pardus Linux 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 GTK GTK+ 2.8.6 GTK GTK+ 2.4.13 GTK GTK+ 2.10.3 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya Messaging Storage Server MM3.0 |
| Not Vulnerable: | |
Discussion
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
Applications using the gtk2 library may be prone to a denial-of-service vulnerability because the library fails to handle malformed image data.
An attacker can exploit this issue to crash applications on a victim's computer.
Applications using the gtk2 library may be prone to a denial-of-service vulnerability because the library fails to handle malformed image data.
An attacker can exploit this issue to crash applications on a victim's computer.
Exploit / POC
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
The following example exploit has been made available. Please see the references for details.
The following example exploit has been made available. Please see the references for details.
Solution / Fix
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
GTK GTK+ 2.10.3
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
GTK GTK+ 2.10.3
-
Mandriva gtk+2.0-2.10.3-5.3mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva gtk+2.0-2.10.3-5.3mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download
References
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
References:
References: