Security update for imlib2
Announcement ID: | SUSE-SU-2016:1481-1 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves five vulnerabilities and has one security fix can now be installed.
Description:
This update for imlib2 fixes the following issues:
Security issues fixed: - CVE-2016-3994: Potential DOS in giflib loader (bsc#973759) - CVE-2016-3993: Off buy 1 in merge update (bsc#973761) - CVE-2014-9764: fix segmentation fault when opening specifically crafted input (bsc#963797) - CVE-2014-9763: Prevent division-by-zero crashes (bsc#963800) - CVE-2011-5326: Ellipse of width 1 triggers crashes (bsc#974202)
Bugs fixed: - bsc#977538: Fix various potential crashes
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Software Development Kit 11 SP4
zypper in -t patch sdksp4-imlib2-12595=1
Package List:
-
SUSE Linux Enterprise Software Development Kit 11 SP4 (s390x x86_64 i586 ppc64 ia64)
- imlib2-filters-1.4.2-2.20.1
- imlib2-loaders-1.4.2-2.20.1
- imlib2-devel-1.4.2-2.20.1
- imlib2-1.4.2-2.20.1
References:
- https://www.suse.com/security/cve/CVE-2011-5326.html
- https://www.suse.com/security/cve/CVE-2014-9763.html
- https://www.suse.com/security/cve/CVE-2014-9764.html
- https://www.suse.com/security/cve/CVE-2016-3993.html
- https://www.suse.com/security/cve/CVE-2016-3994.html
- https://bugzilla.suse.com/show_bug.cgi?id=963797
- https://bugzilla.suse.com/show_bug.cgi?id=963800
- https://bugzilla.suse.com/show_bug.cgi?id=973759
- https://bugzilla.suse.com/show_bug.cgi?id=973761
- https://bugzilla.suse.com/show_bug.cgi?id=974202
- https://bugzilla.suse.com/show_bug.cgi?id=977538