Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Sign up!
EnGarde Community
What is the most important Linux security technology?
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Latest Newsletters
Linux Security Week: January 27th, 2015
Linux Advisory Watch: January 23rd, 2015
LinuxSecurity Newsletters
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

Mandriva: 2011:167: gimp Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Mandrake A vulnerability has been discovered and corrected in gimp: The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte [More...]

 Mandriva Linux Security Advisory                         MDVSA-2011:167

 Package : gimp
 Date    : November 4, 2011
 Affected: 2010.1, 2011., Enterprise Server 5.0

 Problem Description:

 A vulnerability has been discovered and corrected in gimp:
 The LZW decompressor in the LWZReadByte function in giftoppm.c in
 the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw
 function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte
 function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier,
 the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4
 and earlier, and other products, does not properly handle code words
 that are absent from the decompression table when encountered, which
 allows remote attackers to trigger an infinite loop or a heap-based
 buffer overflow, and possibly execute arbitrary code, via a crafted
 compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895
 The updated packages have been patched to correct these issues.


 Updated Packages:

 Mandriva Linux 2010.1:
 6765f41707b43b717ddb8dd3bfa4cdbc  2010.1/i586/gimp-2.6.8-3.2mdv2010.2.i586.rpm
 4c1aab6b423ab88f2fa0bb507a7c60bf  2010.1/i586/gimp-python-2.6.8-3.2mdv2010.2.i586.rpm
 7fd3284b7bc8696ae8075f1a7349c732  2010.1/i586/libgimp2.0_0-2.6.8-3.2mdv2010.2.i586.rpm
 a61333781b8723af9f45dbb94ce9bbb9  2010.1/i586/libgimp2.0-devel-2.6.8-3.2mdv2010.2.i586.rpm 
 f4a4c0635712389d3a438818c3bbde7c  2010.1/SRPMS/gimp-2.6.8-3.2mdv2010.2.src.rpm

 Mandriva Linux 2010.1/X86_64:
 d2ed9cb97e27c8ae7a718b904d442cd1  2010.1/x86_64/gimp-2.6.8-3.2mdv2010.2.x86_64.rpm
 a60fb4df9340ce11a17f8b3c0011c2ac  2010.1/x86_64/gimp-python-2.6.8-3.2mdv2010.2.x86_64.rpm
 55a40dfc4c289c48a0971c4fbb01d395  2010.1/x86_64/lib64gimp2.0_0-2.6.8-3.2mdv2010.2.x86_64.rpm
 dd6d1abb065aa27644b369061f666b0c  2010.1/x86_64/lib64gimp2.0-devel-2.6.8-3.2mdv2010.2.x86_64.rpm 
 f4a4c0635712389d3a438818c3bbde7c  2010.1/SRPMS/gimp-2.6.8-3.2mdv2010.2.src.rpm

 Mandriva Linux 2011:
 40025c9fcafb3d02bd37c92b940c353d  2011/i586/gimp-2.6.11-7.1-mdv2011.0.i586.rpm
 5a3226c6ecdbbae83b90ed9e28c6941a  2011/i586/gimp-python-2.6.11-7.1-mdv2011.0.i586.rpm
 9f156b65a74d0b74538f50b441cc37c4  2011/i586/libgimp2.0_0-2.6.11-7.1-mdv2011.0.i586.rpm
 af0d3a7478773243aa76d99f148b5186  2011/i586/libgimp2.0-devel-2.6.11-7.1-mdv2011.0.i586.rpm 
 4b4024953d52232e1cf0f308dc3a16dc  2011/SRPMS/gimp-2.6.11-7.1.src.rpm

 Mandriva Linux 2011/X86_64:
 f8f0140aebd1666c5d10b09f57de20cc  2011/x86_64/gimp-2.6.11-7.1-mdv2011.0.x86_64.rpm
 d27e9d2ef098ad86d3f68adf1c5f49ca  2011/x86_64/gimp-python-2.6.11-7.1-mdv2011.0.x86_64.rpm
 da1fa7693e5cd7dd8d9807912a61161a  2011/x86_64/lib64gimp2.0_0-2.6.11-7.1-mdv2011.0.x86_64.rpm
 453e8a82d6e7425a7a5e2758a5e6879d  2011/x86_64/lib64gimp2.0-devel-2.6.11-7.1-mdv2011.0.x86_64.rpm 
 4b4024953d52232e1cf0f308dc3a16dc  2011/SRPMS/gimp-2.6.11-7.1.src.rpm

 Mandriva Enterprise Server 5:
 5ca4859d1aab6879d30e6b2188f38d4a  mes5/i586/gimp-2.4.7-1.4mdvmes5.2.i586.rpm
 b6baebc7a47430b09816c43fee81370f  mes5/i586/gimp-python-2.4.7-1.4mdvmes5.2.i586.rpm
 b22ac83c1f8d96d5919aaabe1af9aada  mes5/i586/libgimp2.0_0-2.4.7-1.4mdvmes5.2.i586.rpm
 73b245e8d872bfabaa20787c454e175b  mes5/i586/libgimp2.0-devel-2.4.7-1.4mdvmes5.2.i586.rpm 
 2bc33101108e4bcddd0ccdf6a927958d  mes5/SRPMS/gimp-2.4.7-1.4mdvmes5.2.src.rpm

 Mandriva Enterprise Server 5/X86_64:
 b5083b87e10faef50207e0774dbd4d1c  mes5/x86_64/gimp-2.4.7-1.4mdvmes5.2.x86_64.rpm
 efaa99214382712e2656780b06ef63a0  mes5/x86_64/gimp-python-2.4.7-1.4mdvmes5.2.x86_64.rpm
 008a36ea72e6578a25afd25769893db1  mes5/x86_64/lib64gimp2.0_0-2.4.7-1.4mdvmes5.2.x86_64.rpm
 b30995cb00d18e05a7e4221d0918af15  mes5/x86_64/lib64gimp2.0-devel-2.4.7-1.4mdvmes5.2.x86_64.rpm 
 2bc33101108e4bcddd0ccdf6a927958d  mes5/SRPMS/gimp-2.4.7-1.4mdvmes5.2.src.rpm

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver 0x22458A98

 You can view other update advisories for Mandriva Linux at:

 If you want to report vulnerabilities, please contact

< Prev   Next >


Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
No, Department of Justice, 80 Percent of Tor Traffic Is Not Child Porn
Is your platform secure? Really?
'Mastermind' hacker steals 20 million credentials from dating website
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2015 Guardian Digital, Inc. All rights reserved.