DSA-2029-1 imlib2 -- severalID: oval:org.secpod.oval:def:600120 | Date: (C)2011-01-28 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that imlib2, a library to load and process several image formats, did not properly process various image file types. Several heap and stack based buffer overflows - partly due to integer overflows - in the ARGB, BMP, JPEG, LBM, PNM, TGA and XPM loaders can lead to the execution of arbitrary code via crafted image files. For the stable distribution , this problem has been fixed in version 1.4.0-1.2+lenny1. For the testing distribution , this problem has been fixed in version 1.4.2-1. For the unstable distribution , this problem has been fixed in version 1.4.2-1.