Bug 22422 - gdk-pixbuf2.0 new security issue CVE-2017-1000422
Summary: gdk-pixbuf2.0 new security issue CVE-2017-1000422
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5-64-OK
Keywords: advisory, validated_update
Depends on: 22399
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-19 15:08 CET by David Walser
Modified: 2018-01-21 22:32 CET (History)
1 user (show)

See Also:
Source RPM: gdk-pixbuf2.0-2.32.3-1.1.mga5.src.rpm
CVE: CVE-2017-1000422
Status comment:


Attachments

Description David Walser 2018-01-19 15:08:15 CET
+++ This bug was initially created as a clone of Bug #22399 +++

Debian and Ubuntu have issued advisories on January 15:
https://www.debian.org/security/2018/dsa-4088
https://usn.ubuntu.com/usn/usn-3532-1/

The issue appears to have been fixed upstream in 2.36.11, and Debian and Ubuntu have links to the upstream patch/commit:
https://security-tracker.debian.org/tracker/CVE-2017-1000422
https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000422.html

I would like to fix this core package in Mageia 5; sysadmins, please submit it.
Comment 1 David Walser 2018-01-21 14:57:07 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in
the gif_get_lzw function resulting in memory corruption and potential code
execution (CVE-2017-1000422).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000422
https://www.debian.org/security/2018/dsa-4088
https://usn.ubuntu.com/usn/usn-3532-1/
========================

Updated packages in core/updates_testing:
========================
gdk-pixbuf2.0-2.32.3-1.2.mga5
libgdk_pixbuf2.0_0-2.32.3-1.2.mga5
libgdk_pixbuf2.0-devel-2.32.3-1.2.mga5
libgdk_pixbuf-gir2.0-2.32.3-1.2.mga5

from gdk-pixbuf2.0-2.32.3-1.2.mga5.src.rpm

Assignee: sysadmin-bugs => qa-bugs

Comment 2 David Walser 2018-01-21 16:42:01 CET
Firefox uses this library.  The update only affects GIF decoding, which still works fine in a new Firefox instance after updating on Mageia 5 x86_64.

Whiteboard: (none) => MGA5-64-OK

Lewis Smith 2018-01-21 20:42:27 CET

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 3 Mageia Robot 2018-01-21 22:32:49 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0090.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.