According to summary at $URL: When loading a large gif image, integer overflow may happen in function gif_get_lzw under source file gdk-pixbuf/io-gif.c. Upstream patch: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=0012e066ba37439d402ce46afbc1311530a4ec61 Reproducible: Always
Upstream bug references commits are included in gdk-pixbuf-2.36.11
x86 stable
amd64 stable
Stable on alpha.
Looking good on ppc. Failing builds are only due to +X +introspection needed for gtk+ deps. # cat gdk-pixbuf-644770.report USE tests started on So 21. Jan 14:51:00 CET 2018 USE='-X -introspection -jpeg -jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X -introspection -jpeg -jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X introspection -jpeg -jpeg2k -tiff' succeeded for =x11-libs/gdk-pixbuf-2.36.11 USE='-X introspection jpeg -jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='-X -introspection -jpeg jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X -introspection -jpeg jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='-X introspection -jpeg jpeg2k -tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X introspection -jpeg jpeg2k -tiff' succeeded for =x11-libs/gdk-pixbuf-2.36.11 USE='X -introspection -jpeg -jpeg2k tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='-X -introspection jpeg -jpeg2k tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X -introspection jpeg -jpeg2k tiff' failed for =x11-libs/gdk-pixbuf-2.36.11 USE='X introspection jpeg jpeg2k tiff' succeeded for =x11-libs/gdk-pixbuf-2.36.11 FEATURES= test succeeded for =x11-libs/gdk-pixbuf-2.36.11
commit 9e7f603989bcb17e86282ce69933095d6ed69bc5 Author: Rolf Eike Beer <eike@sf-mail.de> Date: Sat Feb 3 21:50:21 2018 +0100 x11-libs/gdk-pixbuf: stable 2.36.11 for hppa, bug #644770
arm stable
ia64 stable
ppc stable (thanks to ernsteiswuerfel)
ppc64 stable. last arch done
cleanup done
Thanks, Leio! GLSA request filed.
This issue was resolved and addressed in GLSA 201804-14 at https://security.gentoo.org/glsa/201804-14 by GLSA coordinator Aaron Bauman (b-man).