Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200504-17 ] XV: Multiple vulnerabilities
Date: Tue, 19 Apr 2005 05:01:25
Message-Id: 200504190703.33660.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200504-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: XV: Multiple vulnerabilities
9 Date: April 19, 2005
10 Bugs: #88742
11 ID: 200504-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in XV, potentially
19 resulting in the execution of arbitrary code.
20
21 Background
22 ==========
23
24 XV is an interactive image manipulation program for the X Window
25 System.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-gfx/xv < 3.10a-r11 >= 3.10a-r11
34
35 Description
36 ===========
37
38 Greg Roelofs has reported multiple input validation errors in XV image
39 decoders. Tavis Ormandy of the Gentoo Linux Security Audit Team has
40 reported insufficient validation in the PDS (Planetary Data System)
41 image decoder, format string vulnerabilities in the TIFF and PDS
42 decoders, and insufficient protection from shell meta-characters in
43 malformed filenames.
44
45 Impact
46 ======
47
48 Successful exploitation would require a victim to view a specially
49 created image file using XV, potentially resulting in the execution of
50 arbitrary code.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All XV users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose ">=media-gfx/xv-3.10a-r11"
64
65 Availability
66 ============
67
68 This GLSA and any updates to it are available for viewing at
69 the Gentoo Security Website:
70
71 http://security.gentoo.org/glsa/glsa-200504-17.xml
72
73 Concerns?
74 =========
75
76 Security is a primary focus of Gentoo Linux and ensuring the
77 confidentiality and security of our users machines is of utmost
78 importance to us. Any security concerns should be addressed to
79 security@g.o or alternatively, you may file a bug at
80 http://bugs.gentoo.org.
81
82 License
83 =======
84
85 Copyright 2005 Gentoo Foundation, Inc; referenced text
86 belongs to its owner(s).
87
88 The contents of this document are licensed under the
89 Creative Commons - Attribution / Share Alike license.
90
91 http://creativecommons.org/licenses/by-sa/2.0