In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in aniloadchunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdkpixbufset_option() in gdk-pixbuf.c.
{
"binaries": [
{
"binary_version": "2.32.2-1ubuntu1.6+esm1",
"binary_name": "gir1.2-gdkpixbuf-2.0"
},
{
"binary_version": "2.32.2-1ubuntu1.6+esm1",
"binary_name": "libgdk-pixbuf2.0-0"
},
{
"binary_version": "2.32.2-1ubuntu1.6+esm1",
"binary_name": "libgdk-pixbuf2.0-common"
},
{
"binary_version": "2.32.2-1ubuntu1.6+esm1",
"binary_name": "libgdk-pixbuf2.0-dev"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "2.36.11-2ubuntu0.1~esm1",
"binary_name": "gir1.2-gdkpixbuf-2.0"
},
{
"binary_version": "2.36.11-2ubuntu0.1~esm1",
"binary_name": "libgdk-pixbuf2.0-0"
},
{
"binary_version": "2.36.11-2ubuntu0.1~esm1",
"binary_name": "libgdk-pixbuf2.0-bin"
},
{
"binary_version": "2.36.11-2ubuntu0.1~esm1",
"binary_name": "libgdk-pixbuf2.0-common"
},
{
"binary_version": "2.36.11-2ubuntu0.1~esm1",
"binary_name": "libgdk-pixbuf2.0-dev"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "2.40.0+dfsg-3ubuntu0.5",
"binary_name": "gir1.2-gdkpixbuf-2.0"
},
{
"binary_version": "2.40.0+dfsg-3ubuntu0.5",
"binary_name": "libgdk-pixbuf2.0-0"
},
{
"binary_version": "2.40.0+dfsg-3ubuntu0.5",
"binary_name": "libgdk-pixbuf2.0-bin"
},
{
"binary_version": "2.40.0+dfsg-3ubuntu0.5",
"binary_name": "libgdk-pixbuf2.0-common"
},
{
"binary_version": "2.40.0+dfsg-3ubuntu0.5",
"binary_name": "libgdk-pixbuf2.0-dev"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "gdk-pixbuf-tests"
},
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "gir1.2-gdkpixbuf-2.0"
},
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "libgdk-pixbuf-2.0-0"
},
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "libgdk-pixbuf-2.0-dev"
},
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "libgdk-pixbuf2.0-bin"
},
{
"binary_version": "2.42.8+dfsg-1ubuntu0.3",
"binary_name": "libgdk-pixbuf2.0-common"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "gdk-pixbuf-tests"
},
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "gir1.2-gdkpixbuf-2.0"
},
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "libgdk-pixbuf-2.0-0"
},
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "libgdk-pixbuf-2.0-dev"
},
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "libgdk-pixbuf2.0-bin"
},
{
"binary_version": "2.42.10+dfsg-3ubuntu3.1",
"binary_name": "libgdk-pixbuf2.0-common"
}
],
"availability": "No subscription required"
}