Summary: | <x11-libs/gdk-pixbuf-2.34.0: Integer overflow in DecodeHeader causes out-of-bounds heap read in Oneline32 function | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | gnome |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1372204 | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2016-09-06 08:16:47 UTC
This is present in gdk-pixbuf-2.35.3 release. I will backport the patch to 2.34. 2.36 was added to the tree masked with Gnome 3.22. If there is any hurry, I can remove it from mask as it appears to be fine on a stable system, otherwise, I should unmask Gnome 3.22 by this weekend. 2.36 is now unmasked. Feel free to go ahead and stabilize it if needed. PING: The package seems to be stable on all stable arches, and there is no cleanup to do, should we vote for a GLSA and if not necessary close the report? This issue was resolved and addressed in GLSA 201709-08 at https://security.gentoo.org/glsa/201709-08 by GLSA coordinator Aaron Bauman (b-man). |