fedora-security/extras-errata/errata FEDORA-EXTRAS-2006-004, NONE, 1.1

Ville Skytta (scop) fedora-extras-commits at redhat.com
Thu Nov 9 17:30:05 UTC 2006


Author: scop

Update of /cvs/fedora/fedora-security/extras-errata/errata
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv11378/errata

Added Files:
	FEDORA-EXTRAS-2006-004 
Log Message:
FEDORA-EXTRAS-2006-004


--- NEW FILE FEDORA-EXTRAS-2006-004 ---
---------------------------------------------------------------------
Fedora Update Notification
FEDORA-EXTRAS-2006-004
2006-11-09
---------------------------------------------------------------------
Product:    Fedora Extras [3 4 5 6 devel]
Name:       imlib2
Version:    1.2.1-2 [FE 3 4], 1.3.0-3 [FE 5 6 devel]
Summary:    Image loading, saving, rendering, and manipulation library
Description:
Imlib 2 is a library that does image file loading and saving as well
as rendering, manipulation, arbitrary polygon support, etc.
---------------------------------------------------------------------
Update Information:

CVE IDs: CVE-2006-4806, CVE-2006-4807, CVE-2006-4808, CVE-2006-4809

M. Joonas Pihlaja discovered that imlib2 did not sufficiently verify the 
validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images.  If a user 
were tricked into viewing or processing a specially crafted image with 
an application that uses imlib2, the flaws could be exploited to execute 
arbitrary code with the user's privileges.

Fedora Extras versions earlier then the versions mentioned above are
vulnerable to this problem, upgrade to fix this vulnerability.
---------------------------------------------------------------------
This update can be installed with the 'yum' update program.  Use 'yum
update package-name' at the command line.  For more information, refer
to 'Managing Software with yum,' available at
http://fedora.redhat.com/docs/yum/




More information about the scm-commits mailing list