GDK-PixBuf: Remote code execution A vulnerability has been found in GDK-PixBuf that may allow a remote attacker to execute arbitrary code. gdkpixbuf 2018-04-17 2018-04-17 644770 remote 2.36.11 2.36.11

GDK-PixBuf is an image loading library for GTK+.

Several integer overflows were discovered in GDK-PixBuf’s gif_get_lzw function.

A remote attacker, by enticing a user to process a specially crafted image file, could execute arbitrary code or cause a Denial of Service condition.

There is no known workaround at this time.

All GDK-PixBuf users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=x11-libs/gdk-pixbuf-2.36.11"
CVE-2017-1000422 b-man b-man