Debian Security Advisory

DSA-3537-1 imlib2 -- security update

Date Reported:
31 Mar 2016
Affected Packages:
imlib2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-9762, CVE-2014-9763, CVE-2014-9764.
More information:

Several vulnerabilities were discovered in imlib2, an image manipulation library.

  • CVE-2014-9762

    A segmentation fault could occur when opening GIFs without a colormap.

  • CVE-2014-9763

    Several divisions by zero, resulting in a program crash, could occur when handling PNM files.

  • CVE-2014-9764

    A segmentation fault could occur when opening GIFs with feh.

For the oldstable distribution (wheezy), these problems have been fixed in version 1.4.5-1+deb7u1.

For the stable distribution (jessie), these problems have been fixed in version 1.4.6-2+deb8u1.

For the testing (stretch) and unstable (sid) distributions, these problems have been fixed in version 1.4.7-1.

We recommend that you upgrade your imlib2 packages.