Red Hat: imlib security vulnerabilities fix
Posted by Joe Shakespeare   
RedHat Linux Updated imlib packages that fix several integer and buffer overflows are now available.

---------------------------------------------------------------------
                   Red Hat Security Advisory

Synopsis:          Updated imlib packages fix security vulnerabilities
Advisory ID:       RHSA-2004:651-01
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2004-651.html
Issue date:        2004-12-10
Updated on:        2004-12-10
Product:           Red Hat Enterprise Linux
CVE Names:         CAN-2004-1025 CAN-2004-1026
---------------------------------------------------------------------

1. Summary:

Updated imlib packages that fix several integer and buffer overflows are
now available.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

3. Problem description:

The imlib packages contain an image loading and rendering library.

Pavel Kankovsky discovered several heap overflow flaws that were found in
the imlib image handler. An attacker could create a carefully crafted image
file in such a way that it could cause an application linked with imlib to
execute arbitrary code when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1025 to this issue.

Additionally, Pavel discovered several integer overflow flaws that were
found in the imlib image handler. An attacker could create a carefully
crafted image file in such a way that it could cause an application linked
with imlib to execute arbitrary code or crash when the file was opened by a
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1026 to this issue.

Users of imlib should update to these updated packages, which contain
backported patches and are not vulnerable to this issue.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.  Use Red Hat
Network to download and update your packages.  To launch the Red Hat
Update Agent, use the following command:

    up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

    http://www.redhat.com/docs/manuals/enterprise/

5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info):

138516 - CAN-2004-1025 Multiple imlib issues. (CAN-2004-1026)

6. RPMs required:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/imlib-1.9.13-4.3.src.rpm
0a3c30ebe7c7bf1144a5d87762d5b691  imlib-1.9.13-4.3.src.rpm

i386:
a2efcd78207a9773eb0bd31293aa7b24  imlib-1.9.13-4.3.i386.rpm
f05e36c23fcfdc326d1734aaf50fa33c  imlib-cfgeditor-1.9.13-4.3.i386.rpm
ee58781e3e6820560b55b03554a7eab2  imlib-devel-1.9.13-4.3.i386.rpm

ia64:
d6d1ce616e19fbbec8cf3b2f06527a2c  imlib-1.9.13-4.3.ia64.rpm
79a9a717343e73a44efa4198fd8f3856  imlib-cfgeditor-1.9.13-4.3.ia64.rpm
0c87e24aba22c5ebceb6f9f409ba091c  imlib-devel-1.9.13-4.3.ia64.rpm

Red Hat Linux Advanced Workstation 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/imlib-1.9.13-4.3.src.rpm
0a3c30ebe7c7bf1144a5d87762d5b691  imlib-1.9.13-4.3.src.rpm

ia64:
d6d1ce616e19fbbec8cf3b2f06527a2c  imlib-1.9.13-4.3.ia64.rpm
79a9a717343e73a44efa4198fd8f3856  imlib-cfgeditor-1.9.13-4.3.ia64.rpm
0c87e24aba22c5ebceb6f9f409ba091c  imlib-devel-1.9.13-4.3.ia64.rpm

Red Hat Enterprise Linux ES version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/imlib-1.9.13-4.3.src.rpm
0a3c30ebe7c7bf1144a5d87762d5b691  imlib-1.9.13-4.3.src.rpm

i386:
a2efcd78207a9773eb0bd31293aa7b24  imlib-1.9.13-4.3.i386.rpm
f05e36c23fcfdc326d1734aaf50fa33c  imlib-cfgeditor-1.9.13-4.3.i386.rpm
ee58781e3e6820560b55b03554a7eab2  imlib-devel-1.9.13-4.3.i386.rpm

Red Hat Enterprise Linux WS version 2.1:

SRPMS:
ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/imlib-1.9.13-4.3.src.rpm
0a3c30ebe7c7bf1144a5d87762d5b691  imlib-1.9.13-4.3.src.rpm

i386:
a2efcd78207a9773eb0bd31293aa7b24  imlib-1.9.13-4.3.i386.rpm
f05e36c23fcfdc326d1734aaf50fa33c  imlib-cfgeditor-1.9.13-4.3.i386.rpm
ee58781e3e6820560b55b03554a7eab2  imlib-devel-1.9.13-4.3.i386.rpm

Red Hat Enterprise Linux AS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/imlib-1.9.13-13.4.src.rpm
eedcdc9bc78a0736a6db342fb7e064aa  imlib-1.9.13-13.4.src.rpm

i386:
72fad28d75c5beff7140dbe63f33e0b8  imlib-1.9.13-13.4.i386.rpm
286302f2e3965d419772b800436e23cc  imlib-devel-1.9.13-13.4.i386.rpm

ia64:
03d29e218ff542afbea20c1b1332c1ae  imlib-1.9.13-13.4.ia64.rpm
f1a6d86e5bfb55d0efa3c48cdb6e5e60  imlib-devel-1.9.13-13.4.ia64.rpm

ppc:
31e11d994855fe92c394929384ec9b45  imlib-1.9.13-13.4.ppc.rpm
90c3a55b2256f0900e2612ec97059151  imlib-devel-1.9.13-13.4.ppc.rpm

s390:
d51f954de49bafd895a65894e1b808e8  imlib-1.9.13-13.4.s390.rpm
bb4c9944ea49a8c3d865ce2bf7ea4037  imlib-devel-1.9.13-13.4.s390.rpm

s390x:
e932b3c7a39871a5c95db3392fe72c65  imlib-1.9.13-13.4.s390x.rpm
6aae3cebfbdba66a864d6c8e73f76cdb  imlib-devel-1.9.13-13.4.s390x.rpm

x86_64:
207c7bd9f6f3790c8c39a4cd5be65e3d  imlib-1.9.13-13.4.x86_64.rpm
3d2517a397c7e91399e9fe1364740503  imlib-devel-1.9.13-13.4.x86_64.rpm

Red Hat Desktop version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/imlib-1.9.13-13.4.src.rpm
eedcdc9bc78a0736a6db342fb7e064aa  imlib-1.9.13-13.4.src.rpm

i386:
72fad28d75c5beff7140dbe63f33e0b8  imlib-1.9.13-13.4.i386.rpm
286302f2e3965d419772b800436e23cc  imlib-devel-1.9.13-13.4.i386.rpm

x86_64:
207c7bd9f6f3790c8c39a4cd5be65e3d  imlib-1.9.13-13.4.x86_64.rpm
3d2517a397c7e91399e9fe1364740503  imlib-devel-1.9.13-13.4.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/imlib-1.9.13-13.4.src.rpm
eedcdc9bc78a0736a6db342fb7e064aa  imlib-1.9.13-13.4.src.rpm

i386:
72fad28d75c5beff7140dbe63f33e0b8  imlib-1.9.13-13.4.i386.rpm
286302f2e3965d419772b800436e23cc  imlib-devel-1.9.13-13.4.i386.rpm

ia64:
03d29e218ff542afbea20c1b1332c1ae  imlib-1.9.13-13.4.ia64.rpm
f1a6d86e5bfb55d0efa3c48cdb6e5e60  imlib-devel-1.9.13-13.4.ia64.rpm

x86_64:
207c7bd9f6f3790c8c39a4cd5be65e3d  imlib-1.9.13-13.4.x86_64.rpm
3d2517a397c7e91399e9fe1364740503  imlib-devel-1.9.13-13.4.x86_64.rpm

Red Hat Enterprise Linux WS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/imlib-1.9.13-13.4.src.rpm
eedcdc9bc78a0736a6db342fb7e064aa  imlib-1.9.13-13.4.src.rpm

i386:
72fad28d75c5beff7140dbe63f33e0b8  imlib-1.9.13-13.4.i386.rpm
286302f2e3965d419772b800436e23cc  imlib-devel-1.9.13-13.4.i386.rpm

ia64:
03d29e218ff542afbea20c1b1332c1ae  imlib-1.9.13-13.4.ia64.rpm
f1a6d86e5bfb55d0efa3c48cdb6e5e60  imlib-devel-1.9.13-13.4.ia64.rpm

x86_64:
207c7bd9f6f3790c8c39a4cd5be65e3d  imlib-1.9.13-13.4.x86_64.rpm
3d2517a397c7e91399e9fe1364740503  imlib-devel-1.9.13-13.4.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key.html#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1025
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1026

8. Contact:

The Red Hat security contact is .  More contact
details at https://www.redhat.com/security/team/contact.html

Copyright 2004 Red Hat, Inc.