USN-2898-1

Source
https://ubuntu.com/security/notices/USN-2898-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2898-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2898-1
Upstream
Related
Published
2016-02-15T18:20:17.926521Z
Modified
2025-07-16T08:30:20.496323Z
Summary
gtk+2.0, gtk+3.0 vulnerability
Details

It was discovered that GTK+ incorrectly handled certain large images. A remote attacker could use this issue to cause GTK+ applications to crash, resulting in a denial of service, or possibly execute arbitrary code.

References

Affected packages

Ubuntu:14.04:LTS / gtk+2.0

Package

Name
gtk+2.0
Purl
pkg:deb/ubuntu/gtk+2.0@2.24.23-0ubuntu1.4?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.23-0ubuntu1.4

Affected versions

2.*

2.24.20-1ubuntu1
2.24.21-1ubuntu1
2.24.22-1ubuntu1
2.24.22-1ubuntu2
2.24.23-0ubuntu1
2.24.23-0ubuntu1.1
2.24.23-0ubuntu1.2
2.24.23-0ubuntu1.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "gir1.2-gtk-2.0",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "gir1.2-gtk-2.0-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "gtk2-engines-pixbuf",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "gtk2-engines-pixbuf-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "gtk2.0-examples",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "gtk2.0-examples-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-common",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-common-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-dbg",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-dev",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-dev-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail-doc",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail18",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgail18-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-0",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-0-dbg",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-0-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-0-udeb",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-0-udeb-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-bin",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-bin-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-common",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-dev",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-dev-dbgsym",
            "binary_version": "2.24.23-0ubuntu1.4"
        },
        {
            "binary_name": "libgtk2.0-doc",
            "binary_version": "2.24.23-0ubuntu1.4"
        }
    ]
}