| PROBLEM: | A buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service and potentially the execution of arbitrary code. |
| PLATFORM: | Debian GNU/Linux 3.1 (oldstable), 4.0 (stable), and 4.0 (etch) Red Hat Desktop (v. 3, v. 4) Red Hat Enterprise Linux AS, ES, WS (v. 2.1, v.3, v.4) Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor RHEL Desktop Workstation (v. 5 Client) Red Hat Enterprise Linux (v. 5 server) Red Hat Enterprise Linux Desktop (v. 5 client) |
| DAMAGE: | Execution of arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Could lead to denial of service and potentially the execution of arbitrary code. |
REVISION HISTORY:
02/22/2008 - revised S-164 to add links to Red Hat RHSA-2008:0134-3; RHSA-2008:0135-2;
and RHSA-2008:0136-1 for Red Hat Desktop (v. 3, v. 4), Red Hat Enterprise
Linux AS, ES, WS (v. 2.1, v.3, v.4), Red Hat Linux Advanced Workstation
2.1 for the Itanium Processor, RHEL Desktop Workstation (v. 5 Client),
Red Hat Enterprise Linux (v. 5 server), and Red Hat Enterprise Linux
Desktop (v. 5 client).
06/27/2008 - revised S-164 to add a link to Debian Security Advisory DSA-1598-1
for Debian GNU/Linux 4.0 (etch).
[***** Start Debian Security Advisory DSA-1490-1 *****]
It was discovered that a buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service and potentially the execution of arbitrary code.
For the old stable distribution (sarge), this problem has been fixed in version 8.3.5-4sarge1.
For the stable distribution (etch), this problem has been fixed in version 8.3.5-6etch2.
We recommend that you upgrade your tk8.3 packages.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1490-1 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org