| PROBLEM: | Several local/remote vulnerabilities have been discovered in the image loading library for the Simple DirectMedia Layer 1.2. |
| PLATFORM: | Debian GNU/Linux 3.1 (oldstable) and 4.0 (stable) Red Hat Desktop (v. 3, v. 4) Red Hat Enterprise Linus AS, ES, WS (v. 2.1, v.3, v.4) Red Hat Linux Advanced Worstation 2.1 for the Itanium Processor Debian GNU/Linux 4.0 (etch) |
| DAMAGE: | Potentially execute arbitrary code or cause a denial of service. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Could result in denial of service and potentially the execution of arbitary code. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-163.shtml |
| ORIGINAL BULLETIN: | http://www.debian.org/security/2008/dsa-1493 |
| ADDITIONAL LINKS: | https://rhn.redhat.com/errata/RHSA-2008-0131.html http://www.debian.org/security/2008/dsa-1579 |
| CVE: | CVE-2007-6697 CVE-2008-0554 |
REVISION HISTORY:
02/29/2008 - revised S-163 to add a link to Red Hat RHSA-2008:0131-2 for Red Hat
Desktop (v. 3, v. 4); Red Hat Enterprise Linus AS, ES, WS (v. 2.1,
v.3, v.4); and Red Hat Linux Advanced Worstation 2.1 for the Itanium
Processor.
05/20/2008 - revised S-163 to add a link to Debian Security Advisory DSA-1579-1 for
Debian GNU/Linux 4.0 (etch).
[***** Start Debian Security Advisory DSA-1493-1 *****]
Several local/remote vulnerabilities have been discovered in the image loading library for the Simple DirectMedia Layer 1.2. The Common Vulnerabilities and Exposures project identifies the following problems:
Gynvael Coldwind discovered a buffer overflow in GIF image parsing, which could result in denial of service and potentially the execution of arbitrary code.
It was discovered that a buffer overflow in IFF ILBM image parsing could result in denial of service and potentially the execution of arbitrary code.
For the old stable distribution (sarge), these problems have been fixed in version 1.2.4-1etch1. Due to a copy & paste error etch1 was appended to the version number instead of "sarge1". Since the update is otherwise technically correct, the update was not rebuild to the buildd network.
For the stable distribution (etch), these problems have been fixed in version 1.2.5-2etch1.
We recommend that you upgrade your sdl-image1.2 packages.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1493-1 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org