Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuf library used in Gtk. It is possible for an attacker to execute arbitrary code on the victims machine. Gdk-pixbuf for Gtk+1.2 is an external package. For Gtk+2.0 it's part of the main gtk package.
The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities:
Heap-based overflow in pixbuf_create_from_xpm.
Stack-based overflow in xpm_extract_color.
Integer overflow in the ico loader.
For the stable distribution (woody) these problems have been fixed in version 2.0.2-5woody2.
For the unstable distribution (sid) these problems will be fixed soon.
We recommend that you upgrade your Gtk packages.
MD5 checksums of the listed files are available in the original advisory.