The gdk-pixbuf2.0 package has been updated to version 2.36.7, which fixes integer overflows in the ico, bmp, and tiff decoder, as well as fixing other bugs.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0227.json"