USN-6806-1: GDK-PixBuf vulnerability
5 June 2024
GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- gdk-pixbuf - GDK Pixbuf library
Details
Pedro Ribeiro and Vitor Pedreira discovered that the GDK-PixBuf
library did not properly handle certain ANI files. An attacker
could use this flaw to cause GDK-PixBuf to crash, resulting in
a denial of service, or to possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
libgdk-pixbuf2.0-0
-
2.36.11-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
libgdk-pixbuf2.0-0
-
2.32.2-1ubuntu1.6+esm1
Available with Ubuntu Pro
After a standard system update you need to restart your session to make all
the necessary changes.