| Summary: | media-libs/imlib < 1.9.15-r2, emul-linux-x86-gtklibs Denial of Service via network with a BMP image (CVE-2007-3568) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Peter Volkov (RETIRED) <pva> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | CC: | desktop-misc |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3568 | ||
| Whiteboard: | B3 [noglsa] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Peter Volkov (RETIRED)
2007-12-10 19:39:23 UTC
Updated imlib-1.9.15-r2 which includes the fix is in portage. Please, review and proceed as required. Assigning on security as this is security issue. Thanks Peter. Arches, please test and mark stable media-libs/imlib-1.9.15-r2. Target "alpha amd64 arm hppa ia64 mips ppc ppc64 sh sparc x86 ~x86-fbsd" Amd64, this also affects emul-linux-x86-gtklibs. Please update. x86 stable Stable for sparc. Stable for HPPA. alpha/ia64 stable Ebuild stable on amd64, emul stuff yet to come. Bumped app-emulation/emul-linux-x86-gtklibs - amd64 guys, please test and stable. (If the tarball hasn't yet hit the mirrors, fetch it from here: http://dev.gentoo.org/~welp/emul-linux-x86-gtklibs-20071214.tar.bz2) ppc64 stable ppc stable emul-linux-x86-gtklibs-20071214 (which contains the fix) is stable on amd64, thanks to gentoofan23 for testing. Ready for glsa vote. Since this library and function is very unlikely to be called from remote, I vote NO here. no too, and closing. Does not affect current (2008.0) release. Removing release. |