Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Ubuntu update for libungif Advisory Available in Danish 

Secunia Advisory: SA17488  
Release Date: 2005-11-08
Last Update: 2005-11-09

Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Ubuntu Linux 4.10
Ubuntu Linux 5.04


CVE reference:CVE-2005-2974 (Secunia mirror)
CVE-2005-3350 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Ubuntu has issued an update for libungif4g. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.

For more information:
SA17436

Solution:
Apply updated packages.

-- Ubuntu 4.10 (Warty Warthog) --

Source archives:

http://security.ubuntu.com/ubuntu/poo.../libungif4_4.1.0b1-6ubuntu0.1.diff.gz
Size/MD5: 299066 b1e73895c7e0ad79c0e19e6cdc17e0a0
http://security.ubuntu.com/ubuntu/poo...gif4/libungif4_4.1.0b1-6ubuntu0.1.dsc
Size/MD5: 654 e77c0c985a9a69be2306521c68c90948
http://security.ubuntu.com/ubuntu/poo...bungif4/libungif4_4.1.0b1.orig.tar.gz
Size/MD5: 351757 20d96eb90cf818a1da093614c44ad3e5

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...ngif-bin_4.1.0b1-6ubuntu0.1_amd64.deb
Size/MD5: 220664 20b10d4a5722c313fb9087e9637d3932
http://security.ubuntu.com/ubuntu/poo...gif4-dev_4.1.0b1-6ubuntu0.1_amd64.deb
Size/MD5: 36512 7267a1987fbabd4933e000ccb1506db3
http://security.ubuntu.com/ubuntu/poo...bungif4g_4.1.0b1-6ubuntu0.1_amd64.deb
Size/MD5: 52450 e518ccb9521345253a7195baf59d304c

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...ungif-bin_4.1.0b1-6ubuntu0.1_i386.deb
Size/MD5: 202984 f68d125ce049c9507756e83bad2549dc
http://security.ubuntu.com/ubuntu/poo...ngif4-dev_4.1.0b1-6ubuntu0.1_i386.deb
Size/MD5: 34294 3b22cf5ce6d91f4f9f1c27e9a9ec6d75
http://security.ubuntu.com/ubuntu/poo...ibungif4g_4.1.0b1-6ubuntu0.1_i386.deb
Size/MD5: 51064 ce716cf26fdc0b27230dafea49d005c0

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...if-bin_4.1.0b1-6ubuntu0.1_powerpc.deb
Size/MD5: 235062 acc2f9eb7dfc2a0f1e4551a2217fc579
http://security.ubuntu.com/ubuntu/poo...f4-dev_4.1.0b1-6ubuntu0.1_powerpc.deb
Size/MD5: 36562 84f4b4a0ed7e5f5a35b9ac7789e70a3e
http://security.ubuntu.com/ubuntu/poo...ngif4g_4.1.0b1-6ubuntu0.1_powerpc.deb
Size/MD5: 53420 c0b95884ad01a6ec49aa4a0fbbd71411

-- Ubuntu 5.04 (Hoary Hedgehog) --

Source archives:

http://security.ubuntu.com/ubuntu/poo...f4/libungif4_4.1.3-1ubuntu0.1.diff.gz
Size/MD5: 27712 4835a55c199b8bad795cb36ccd844b32
http://security.ubuntu.com/ubuntu/poo...ungif4/libungif4_4.1.3-1ubuntu0.1.dsc
Size/MD5: 639 7a91eda1b7d0ec48c26f69518e6787f9
http://security.ubuntu.com/ubuntu/poo...libungif4/libungif4_4.1.3.orig.tar.gz
Size/MD5: 569667 cb11e300347ad29e502abc6f56fd23df

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...bungif-bin_4.1.3-1ubuntu0.1_amd64.deb
Size/MD5: 224438 efe72b94ed939de9b85e556e07fb228d
http://security.ubuntu.com/ubuntu/poo...ungif4-dev_4.1.3-1ubuntu0.1_amd64.deb
Size/MD5: 41158 381aaff6c58f9402275bf37cf3c58abf
http://security.ubuntu.com/ubuntu/poo...libungif4g_4.1.3-1ubuntu0.1_amd64.deb
Size/MD5: 57506 88918dea5ab32a782a8e1d731a4b4f24

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...ibungif-bin_4.1.3-1ubuntu0.1_i386.deb
Size/MD5: 206076 a81c6995f1e3ebbba7ce725171574b59
http://security.ubuntu.com/ubuntu/poo...bungif4-dev_4.1.3-1ubuntu0.1_i386.deb
Size/MD5: 38928 8def52728fce5ef3fcaf3137c3cd2ce3
http://security.ubuntu.com/ubuntu/poo.../libungif4g_4.1.3-1ubuntu0.1_i386.deb
Size/MD5: 56194 474750d2fddcf82434a136014e1cb2d9

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...ngif-bin_4.1.3-1ubuntu0.1_powerpc.deb
Size/MD5: 238938 f36748ba01f1527ef18be9ccf8c51456
http://security.ubuntu.com/ubuntu/poo...gif4-dev_4.1.3-1ubuntu0.1_powerpc.deb
Size/MD5: 41242 892f389e108ca0bfbe0346341c88817b
http://security.ubuntu.com/ubuntu/poo...bungif4g_4.1.3-1ubuntu0.1_powerpc.deb
Size/MD5: 58440 ed9a1b67bcb7165b6cb4f70048c00ca4

Changelog:
2005-11-09: Updated link to original advisory.

Original Advisory:
http://www.ubuntulinux.org/usn/usn-214-1

Other References:
SA17436:
http://secunia.com/advisories/17436/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

266 Related Secunia Security Advisories, displaying 10

1. Ubuntu update for screen
2. Ubuntu update for Ruby
3. Ubuntu update for imagemagick
4. Ubuntu update for Qt
5. Ubuntu update for pike
6. Ubuntu update for libksba
7. Ubuntu update for libmusicbrainz
8. Ubuntu update for mozilla
9. Ubuntu update for php4 and php5
10. Ubuntu update for awstats

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
dotProject SQL Injection and Cross-Site Scripting
2.
HP TCP/IP Services for OpenVMS Finger Format String Vulnerability
3.
Sun Solaris Kernel Covert Channel Security Bypass
4.
Red Hat update for libtiff
5.
Novell eDirectory Multiple Vulnerabilities
6.
Adium MSN SLP Message Integer Overflow Vulnerabilities
7.
Ultra Office ActiveX Control Multiple Vulnerabilities
8.
IBM WebSphere Application Server for z/OS HTTP Server mod_proxy_ftp Vulnerability
9.
GpsDrive "geo-code" Insecure Temporary Files
10.
Caudium "configvar" Insecure Temporary Files





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia