Описание
Security update for gdk-pixbuf
This update for gdk-pixbuf fixes the following issues:
- CVE-2017-2862: JPEG gdk_pixbuf__jpeg_image_load_increment Code Execution Vulnerability (bsc#1048289)
- CVE-2017-2870: tiff_image_parse Code Execution Vulnerability (bsc#1048544)
- CVE-2017-6313: A dangerous integer underflow in io-icns.c (bsc#1027024)
- CVE-2017-6314: Infinite loop in io-tiff.c (bsc#1027025)
- CVE-2017-6312: Out-of-bounds read on io-ico.c (bsc#1027026)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2017:2381-1
- E-Mail link for SUSE-SU-2017:2381-1
- SUSE Security Ratings
- SUSE Bug 1027024
- SUSE Bug 1027025
- SUSE Bug 1027026
- SUSE Bug 1048289
- SUSE Bug 1048544
- SUSE Bug 1049877
- SUSE CVE CVE-2017-2862 page
- SUSE CVE CVE-2017-2870 page
- SUSE CVE CVE-2017-6312 page
- SUSE CVE CVE-2017-6313 page
- SUSE CVE CVE-2017-6314 page
Описание
An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2017-2862
- SUSE Bug 1048289
Описание
An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2017-2870
- SUSE Bug 1048289
- SUSE Bug 1048544
Описание
Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.
Затронутые продукты
Ссылки
- CVE-2017-6312
- SUSE Bug 1027024
- SUSE Bug 1027026
Описание
Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.
Затронутые продукты
Ссылки
- CVE-2017-6313
- SUSE Bug 1027024
Описание
The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
Затронутые продукты
Ссылки
- CVE-2017-6314
- SUSE Bug 1027024
- SUSE Bug 1027025