Freedom The Open Source Way Contribute Articles or News to OSForgeOSForge HomeLogout from Forums
Contacting OSForgeOSForge HomeAbout OSForge
  

Root
Contribute News
Learning Corner
Linux Distributions
Linux Common FAQ's
Discussion Forums
Community Gallery
Links Directory
Search OSForge
Networking
Industry Updates
Linux & Open Source
Opinions
Press Release
Programming
Security
Web Development

White Paper
Open-Xchange to Deliver Collaboration Solution Integrated With Parallels Automation
OpenKM - Document Mangement announces version 2.0
SugarCRM Manages End-to-End SaaS Offering with Zenoss
Linux Foundation’s Annual Collaboration Summit Kicks Off
Engine Yard Kicks Off Hackfest Series for Ruby Developers
Plat'Home Launches First Linux-based Eco-Friendly Servers In United States
World’s Largest Python Conference Sees 70 Percent Jump in Attendance
Leading SaaS Infrastructure Provider Deploys Zenoss to Improve Uptime and Reduce Cost
JasperSoft is Most Widely-Deployed Business Intelligence Software in the World

View More »

Conectiva Linux Announcement: imlib
By : Eric Lim [www] Find more article by Eric Lim on Security
Thursday the 9th, May 2002 at 05:31 AM (EDT)
Send this Story to a Friend Readers TalkBack (0) - 658 Reads

Printer Friendly Page Printable format
Send this Story to a Friend Foward to Email

Conectiva Linux Announcement: imlib

- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------

PACKAGE   : imlib
SUMMARY   : Potential vulnerabilities in imlib
DATE      : 2002-05-08 13:25:00
ID        : CLA-2002:481
RELEVANT
RELEASES  : 8

- -------------------------------------------------------------------------

DESCRIPTION
Imlib is a library that allows X11 programs to use images of various
file formats.

Alan Cox discovered some situations where a heap corruption[1] may
occur when processing some malformed image.
Al Viro found that imlib was falling back to the NetPBM library[2]
when processing some kind of images, but NetPBM is not suitable to
process untrusted image input.

An attacker could use a crafted image to exploit a program linked to
imlib (like a mailer program or an image viewer) and cause a DoS or
even remote code execution.

This update to imlib 1.9.14 solves both problems and adds some fixes
from the imlib developers.

Notice that the update[3] for Conectiva Linux versions prior to 8 was
released on 03/28/2002.


SOLUTION
All users of imlib should do the upgrade. Notice that the
vulnerabilities can be exploited through programs linked to imlib
(like the "Electric Eyes" image viewer), so you should restart them
in order to load the updated imlib.


REFERENCES:
1.http://online.securityfocus.com/bid/4336
2.http://online.securityfocus.com/bid/4339
3.http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000470

DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/8/RPMS/imlib-1.9.14-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/imlib-cfgeditor-1.9.14-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/imlib-devel-1.9.14-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/imlib-devel-static-1.9.14-1U8_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/imlib-1.9.14-1U8_1cl.src.rpm


ADDITIONAL INSTRUCTIONS
Users of Conectiva Linux version 6.0 or higher may use apt to perform
upgrades of RPM packages:
- add the following line to /etc/apt/sources.list if it is not there yet
   (you may also use linuxconf to do this):

rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates

(replace 6.0 with the correct version number if you are not running CL6.0)

- run:                 apt-get update
- after that, execute: apt-get upgrade

Detailed instructions reagarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en


- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en

  
Reader Rating from 1-5

 

Poor very 

1

2

3

4

5
 very Excellent

Talkback

Post Your Talkback | View All Talkback (0 Posted)


 Currently there are no Talkback posted on "Conectiva Linux Announcement: imlib", Click here to be the first to post a talkback.


 
Scroll Up

   About | Term of Use | Privacy | Contact us | Tell a Friend | Advertise  

OSForge News RSS Feed