Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· The third screen: Will all Windows 8 apps run on Microsoft's Xbox One?
· CentOS-6.4 LiveCD and LiveDVD for i386 and x86_64 released
· Apple OS X malware outbreak could give UK firms a bad Hangover
· 5 Modem At Command Examples in Linux (How to Configure Minicom)
· CompatDB Updates 05/22/13
· Removing and Wiping Drivers Guide and more
· Windows Server 2012 Essentials SDK Installer 1.1
· Xbox One hardware and specs: 8-core CPU, 8GB RAM, 500GB hard drive and more
· Tim Cook: US-made Macs will be assembled in Texas
· Microsoft software satisfaction slumps

Upcoming News
· AMD 2013 A and E-Series Kabini and Temash Mobile APUs @ HotHardware.com
· AllPuter.com product launch: OEM Apple Lightning 8pin with 3.5mm Aux to 30pin Dock Converter
· AMD Kabini, Temash and Richland Information Overload
· ZOTAC GeForce GTX 680 AMP! Edition Graphics Card Review @ HardwareHeaven.com
· SanDisk Ultra Plus 256GB SSD Review
· What’s Wrong with the Xbox One? @ TestFreaks
· [CentOS-announce] CEBA-2013:0857 CentOS 6 qemu-kvm Update
· REVIEW: ECS A970M-A Deluxe @ PureOverclock
· For Father's Day Gifts Articles/Shows: SensoGlove Lets Da?= ds Finally Improve Their Golf Game
· Far Cry 3: Blood Dragon Review @ OCC

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6432 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 685 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4550 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 755 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1139 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2004 » USN-33-1: libgd vulnerabilities

USN-33-1: libgd vulnerabilities

Posted by Philipp Esselbach on: 11/29/2004 05:31 PM [ Print | 0 comment(s) ]

A libgd security update has been released for Ubuntu Linux 4.10

==========================================================
Ubuntu Security Notice USN-33-1 November 29, 2004
libgd vulnerabilities
CAN-2004-0941
==========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

libgd1-noxpm
libgd1-xpm

The problem can be corrected by upgrading the affected package to version 1.8.4-36ubuntu0.2. In general, a standard system upgrade is sufficient to effect the necessary changes.




Details follow:

CAN-2004-0990 described several buffer overflows which had been discovered in libgd's PNG handling functions. Another update is required because the update from USN-21-1 was not sufficient to prevent every possible attack.

If an attacker tricks a user into loading a malicious PNG or XPM image, they could leverage this into executing arbitrary code in the context of the user opening image.

This vulnerability might lead to privilege escalation in customized systems that use server applications which link libgd. However, Warty does not ship such server applications (PHP in Warty uses libgd2 which was already fixed in USN-25-1).

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd_1.8.4-36ubuntu0.2.diff.gz
Size/MD5: 12323 a786097a746555a53b25ce68168e6878
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd_1.8.4-36ubuntu0.2.dsc
Size/MD5: 775 7324e0a3fcb79df8fc367537a1bcd539
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd_1.8.4.orig.tar.gz
Size/MD5: 559248 813625508e31f5c205904a305bdc8669

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-dev_1.8.4-36ubuntu0.2_all.deb
Size/MD5: 8746 9d7dca3cd8a0171b9eb796ec4e9a9461
http://security.ubuntu.com/ubuntu/pool/universe/libg/libgd/libgd1_1.8.4-36ubuntu0.2_all.deb
Size/MD5: 8734 4735c7dae226eaf3c819b7f6dbbfb67e

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-noxpm-dev_1.8.4-36ubuntu0.2_amd64.deb
Size/MD5: 118450 5cbb047f22d7d8eb771f09cec74cf0f0
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-xpm-dev_1.8.4-36ubuntu0.2_amd64.deb
Size/MD5: 119270 3d8aea0f13bb288174487ad487d788de
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-noxpm_1.8.4-36ubuntu0.2_amd64.deb
Size/MD5: 111854 31b3f62f7cd6639f7db15d63c9091182
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-xpm_1.8.4-36ubuntu0.2_amd64.deb
Size/MD5: 112230 35abed9e9948c515747378f22ca08c6a

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-noxpm-dev_1.8.4-36ubuntu0.2_i386.deb
Size/MD5: 113724 01a746e583a1e266bbde6893105dde5b
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-xpm-dev_1.8.4-36ubuntu0.2_i386.deb
Size/MD5: 114278 c9db1035361d8914f474e4b341e8bc21
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-noxpm_1.8.4-36ubuntu0.2_i386.deb
Size/MD5: 108898 a1a0ffeb8f1cb031a906ebc2e17f0c41
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-xpm_1.8.4-36ubuntu0.2_i386.deb
Size/MD5: 109292 ef94e51d4719648a973411d41ce2317a

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-noxpm-dev_1.8.4-36ubuntu0.2_powerpc.deb
Size/MD5: 119708 643239574e7134987e21134b517c0200
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd-xpm-dev_1.8.4-36ubuntu0.2_powerpc.deb
Size/MD5: 120574 ed210cf839bc582029806a176d58eaad
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-noxpm_1.8.4-36ubuntu0.2_powerpc.deb
Size/MD5: 113216 d058c407f5ec26a315c1b6f439721c8c
http://security.ubuntu.com/ubuntu/pool/main/libg/libgd/libgd1-xpm_1.8.4-36ubuntu0.2_powerpc.deb
Size/MD5: 113510 709808f36db560407c78a4f9e90408b8


Bookmark and Share

« Inphi Corporation Strengthens Market Lead With Launch of Industry’s Fastest DDR · Sid Meier's Pirates Review »

Linux Compatible » News » November 2004 » USN-33-1: libgd vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition