A CVE has been assigned for a security issue in gdk-pixbuf2.0: http://openwall.com/lists/oss-security/2016/07/26/11 The upstream bug is here: https://bugzilla.gnome.org/show_bug.cgi?id=769170 There is no fix available yet. Mageia 5 is also affected.
Whiteboard: (none) => MGA5TOO
Assigning to all packagers collectively, since there is no maintainer for this package.
CC: (none) => marja11Assignee: bugsquad => pkg-bugs
openSUSE has issued an advisory for this today (September 9): https://lists.opensuse.org/opensuse-updates/2016-09/msg00040.html Patched packages uploaded for Mageia 5 and Cauldron. Mageia 5 was also updated to 2.32.3 (as was openSUSE). Advisory: ======================== Updated gdk-pixbuf2.0 packages fix security vulnerability: A write out-of-bounds parsing an ico file was found in gdk-pixbuf. A maliciously crafted file can cause the application to crash (CVE-2016-6352). The gdk-pixbuf2.0 package has been updated to version 2.32.3 and patched to fix this issue, and a few other possible security issues. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6352 https://git.gnome.org/browse/gdk-pixbuf/tree/NEWS?h=gdk-pixbuf-2-32&id=c09a36169fdb97fcb937acc7c08909b1fb99e952 https://lists.opensuse.org/opensuse-updates/2016-09/msg00040.html ======================== Updated packages in core/updates_testing: ======================== gdk-pixbuf2.0-2.32.3-1.mga5 libgdk_pixbuf2.0_0-2.32.3-1.mga5 libgdk_pixbuf2.0-devel-2.32.3-1.mga5 libgdk_pixbuf-gir2.0-2.32.3-1.mga5 from gdk-pixbuf2.0-2.32.3-1.mga5.src.rpm
URL: (none) => http://lwn.net/Vulnerabilities/700113/Version: Cauldron => 5Assignee: pkg-bugs => qa-bugsWhiteboard: MGA5TOO => (none)Severity: normal => major
Testing Mageia 5 x64 real hardware with AMD/ATI/Radeon graphics From bug 18476: "To test, make sure Firefox can load images OK." Updated from version -2.32.1-1.1 to: gdk-pixbuf2.0-2.32.3-1.mga5 lib64gdk_pixbuf-gir2.0-2.32.3-1.mga5 lib64gdk_pixbuf2.0_0-2.32.3-1.mga5 lib64gdk_pixbuf2.0-devel-2.32.3-1.mga5 Using Firefox, looked at a selection of on-line JPEG, GIF & PNG images. Everything seems OK.
CC: (none) => lewyssmithWhiteboard: (none) => MGA5-64-OK
Updated gdk-pixbuf packages on i586 virtualbox. Loaded images in Firefox from astronomical sites and local image directory to test various formats; PNG, JPEG, SVG, GIF, PNG, ICO. Bitmap images would not load but they probably don't anyway. This looks OK.
CC: (none) => tarazed25
Whiteboard: MGA5-64-OK => MGA5-64-OK MGA5-32-OK
Validating this update; advisory to follow.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2016-0322.html
Status: NEW => RESOLVEDResolution: (none) => FIXED