Freedom The Open Source Way Contribute Articles or News to OSForgeOSForge HomeLogout from Forums
Contacting OSForgeOSForge HomeAbout OSForge
  

Root
Contribute News
Learning Corner
Linux Distributions
Linux Common FAQ's
Discussion Forums
Community Gallery
Links Directory
Search OSForge
Networking
Industry Updates
Linux & Open Source
Opinions
Press Release
Programming
Security
Web Development

White Paper
Plat'Home Unveils Winners of “Will Linux Work?” Contest
Zenoss Core Recognized as Best Open Source Network Monitoring Solution
LinMin™ Joins Intel® Certified Software Solutions Program
xTuple™ ERP 3.0 Wins “Best Business Application” At LinuxWorld Conference & Exp
Holland Computing Center - Rocks+Moab Provides Windows/Linux Cluster Solution
LogMeIn Launches Mobile Plug-in for Linux
FuseMail Selects Funambol’s Open Source Push Email and PIM Sync Solution
Zenoss Expands IT Management Solution for Managed Service Providers
Moab Workload Manager Claims Title as World’s First Petaflop Scheduler

View More

Caldera Linux Advisory: imlib processes untrusted images
By : Eric Lim [www] Find more article by Eric Lim on Security
Wednesday the 1st, May 2002 at 05:06 PM (EDT)
Send this Story to a Friend Readers TalkBack (0) - 777 Reads

Printer Friendly Page Printable format
Send this Story to a Friend Foward to Email

Caldera Linux Advisory: imlib processes untrusted images

____________________________________________________________________________

                Caldera International, Inc.  Security Advisory

Subject:                Linux: imlib processes untrusted images
Advisory number:        CSSA-2002-019.0
Issue date:             2002 April 29
Cross reference:
____________________________________________________________________________


1. Problem Description

        Imlib versions prior to 1.9.13 would fall back to loading images
        via the NetPBM package. NetPBM has various problems itself
        that make it unsuitable for loading untrusted images. This
        may allow attackers to construct images that, when loaded by
        a viewer using Imlib, could cause crashes or potentially, the
        execution of arbitrary code.

        In addition, this version (1.9.14) also includes some further
        fixes from the imlib team.


2. Vulnerable Supported Versions

        System                          Package
        ----------------------------------------------------------------------

        OpenLinux 3.1.1 Server          prior to imlib-1.9.14-1.i386.rpm
                                        prior to imlib-devel-1.9.14-1.i386.rpm

        OpenLinux 3.1.1 Workstation     prior to imlib-1.9.14-1.i386.rpm
                                        prior to imlib-devel-1.9.14-1.i386.rpm

        OpenLinux 3.1 Server            prior to imlib-1.9.14-1.i386.rpm
                                        prior to imlib-devel-1.9.14-1.i386.rpm

        OpenLinux 3.1 Workstation       prior to imlib-1.9.14-1.i386.rpm
                                        prior to imlib-devel-1.9.14-1.i386.rpm


3. Solution

        The proper solution is to install the latest packages.


4. OpenLinux 3.1.1 Server

        4.1 Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS

        4.2 Packages

        56ed4f4cdf53abc39ba462021496314b        imlib-1.9.14-1.i386.rpm
        743951ea75a12121f6696a57a6a4d091        imlib-devel-1.9.14-1.i386.rpm

        4.3 Installation

        rpm -Fvh imlib-1.9.14-1.i386.rpm
        rpm -Fvh imlib-devel-1.9.14-1.i386.rpm

        4.4 Source Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/SRPMS

        4.5 Source Packages

        7f31fe77f6e8086aced4bb412b46e55c        imlib-1.9.14-1.src.rpm


5. OpenLinux 3.1.1 Workstation

        5.1 Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS

        5.2 Packages

        de20299b700ab3918bed0c782abcd6c3        imlib-1.9.14-1.i386.rpm
        ba96a381bb7c60f20ce74b5645c02fa8        imlib-devel-1.9.14-1.i386.rpm

        5.3 Installation

        rpm -Fvh imlib-1.9.14-1.i386.rpm
        rpm -Fvh imlib-devel-1.9.14-1.i386.rpm

        5.4 Source Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/SRPMS

        5.5 Source Packages

        060c0a51023524bb1681ac6b68405bd7        imlib-1.9.14-1.src.rpm


6. OpenLinux 3.1 Server

        6.1 Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS

        6.2 Packages

        72ab762b5b78035581fa9200cac775d7        imlib-1.9.14-1.i386.rpm
        7e918173391601c5df401be3c7644a78        imlib-devel-1.9.14-1.i386.rpm

        6.3 Installation

        rpm -Fvh imlib-1.9.14-1.i386.rpm
        rpm -Fvh imlib-devel-1.9.14-1.i386.rpm

        6.4 Source Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/SRPMS

        6.5 Source Packages

        4c864ed09fd05a3740e3a8d6acab2349        imlib-1.9.14-1.src.rpm


7. OpenLinux 3.1 Workstation

        7.1 Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RPMS

        7.2 Packages

        0e03563711a6c9902b6d7d2016a45c84        imlib-1.9.14-1.i386.rpm
        d0bbec107ff9b58d8851a0cb680bedf3        imlib-devel-1.9.14-1.i386.rpm

        7.3 Installation

        rpm -Fvh imlib-1.9.14-1.i386.rpm
        rpm -Fvh imlib-devel-1.9.14-1.i386.rpm

        7.4 Source Package Location

        ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/SRPMS

        7.5 Source Packages

        5eed6f4ffeeebf13e266a4078bc45442        imlib-1.9.14-1.src.rpm


8. References

        Specific references for this advisory:
                none

        Caldera OpenLinux security resources:
                http://www.caldera.com/support/security/index.html

        Caldera UNIX security resources:
                http://stage.caldera.com/support/security/

        This security fix closes Caldera incidents sr862212, fz520437,
        erg712001.


9. Disclaimer

        Caldera International, Inc. is not responsible for the misuse
        of any of the information we provide on this website and/or
        through our security advisories. Our advisories are a service
        to our customers intended to promote secure installation and
        use of Caldera products.


10. Acknowledgements

        Alan Cox and Al Viro discovered and researched the
        vulnerabilities.

____________________________________________________________________________

  
Reader Rating from 1-5

 

Poor very 

1

2

3

4

5
 very Excellent

Talkback

Post Your Talkback | View All Talkback (0 Posted)


 Currently there are no Talkback posted on "Caldera Linux Advisory: imlib processes untrusted images", Click here to be the first to post a talkback.


 
Scroll Up

   About | Term of Use | Privacy | Contact us | Tell a Friend | Advertise  

OSForge News RSS Feed