Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Mailing Lists RSS Blog New entry Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)
  - NEW -

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Ubuntu update for sdl-image Advisory Available in German 

Secunia Advisory: SA29542  
Release Date: 2008-03-27

Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Ubuntu Linux 6.06
Ubuntu Linux 6.10
Ubuntu Linux 7.04
Ubuntu Linux 7.10


CVE reference:CVE-2007-6697 (Secunia mirror)
CVE-2008-0544 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Ubuntu has issued an update for sdl-image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

For more information:
SA28640

Solution:
Apply updated packages.

-- Ubuntu 6.06 LTS --

Source archives:

http://security.ubuntu.com/ubuntu/poo...sdl-image1.2_1.2.4-1ubuntu0.1.diff.gz
Size/MD5:27731 f25861d21b3b2222ff604b849c3842fb
http://security.ubuntu.com/ubuntu/poo...1.2/sdl-image1.2_1.2.4-1ubuntu0.1.dsc
Size/MD5:703 4a7bab926b499874e626476a24d59192
http://security.ubuntu.com/ubuntu/poo...age1.2/sdl-image1.2_1.2.4.orig.tar.gz
Size/MD5: 841885 70bf617f99e51a2c94550fc79d542f0b

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...age1.2-dev_1.2.4-1ubuntu0.1_amd64.deb
Size/MD5:34740 ab68facb50821f78f5d4511bce334a51
http://security.ubuntu.com/ubuntu/poo...l-image1.2_1.2.4-1ubuntu0.1_amd64.deb
Size/MD5:28972 1e1a9448740510f93fe01bd88d46b502

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...mage1.2-dev_1.2.4-1ubuntu0.1_i386.deb
Size/MD5:31012 e838fe7522ad48cdfc95bfdc73de320f
http://security.ubuntu.com/ubuntu/poo...dl-image1.2_1.2.4-1ubuntu0.1_i386.deb
Size/MD5:26768 93e3957bb91a6268bb1030155f955f4d

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...e1.2-dev_1.2.4-1ubuntu0.1_powerpc.deb
Size/MD5:35198 117d57af8e4ce8e55315dcfd9749ebf3
http://security.ubuntu.com/ubuntu/poo...image1.2_1.2.4-1ubuntu0.1_powerpc.deb
Size/MD5:29798 60d44fc21e806b31c03760aebcf14b64

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...age1.2-dev_1.2.4-1ubuntu0.1_sparc.deb
Size/MD5:32956 fede4369525cfe7e1b0f03c95a700ba7
http://security.ubuntu.com/ubuntu/poo...l-image1.2_1.2.4-1ubuntu0.1_sparc.deb
Size/MD5:27422 7adb8093da72732c65ce0dc0bb76d932

-- Ubuntu 6.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...mage1.2_1.2.5-2ubuntu0.6.10.1.diff.gz
Size/MD5:12438 722a44ed315b6bd0761bd4b55491b4c2
http://security.ubuntu.com/ubuntu/poo...dl-image1.2_1.2.5-2ubuntu0.6.10.1.dsc
Size/MD5:715 ed059f756a27f70abad413f43813dfe6
http://security.ubuntu.com/ubuntu/poo...age1.2/sdl-image1.2_1.2.5.orig.tar.gz
Size/MD5:1308637 cd006109a73bf7dcc93e1c3ed15ee782

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...2-dev_1.2.5-2ubuntu0.6.10.1_amd64.deb
Size/MD5:38162 e70127ca5a699f4ae80d25f4393eb2b1
http://security.ubuntu.com/ubuntu/poo...ge1.2_1.2.5-2ubuntu0.6.10.1_amd64.deb
Size/MD5:31304 9d1e30e1dbc8a47d50347fec9e2ae308

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo....2-dev_1.2.5-2ubuntu0.6.10.1_i386.deb
Size/MD5:34772 25d73b30f2fad8dbb592446b623d10d4
http://security.ubuntu.com/ubuntu/poo...age1.2_1.2.5-2ubuntu0.6.10.1_i386.deb
Size/MD5:29518 b0a4357caad50210e006d5714e9ba4ce

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...dev_1.2.5-2ubuntu0.6.10.1_powerpc.deb
Size/MD5:39348 b68e0281277b12ee0b60ac03a9793d9f
http://security.ubuntu.com/ubuntu/poo...1.2_1.2.5-2ubuntu0.6.10.1_powerpc.deb
Size/MD5:32732 d0d78d804a532f8fdef5458317871f9f

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...2-dev_1.2.5-2ubuntu0.6.10.1_sparc.deb
Size/MD5:36452 1fe5217484b152f2fe564e82ebbbc94b
http://security.ubuntu.com/ubuntu/poo...ge1.2_1.2.5-2ubuntu0.6.10.1_sparc.deb
Size/MD5:29856 bcad33139b674dd652af6fcc48c607a8

-- Ubuntu 7.04 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...mage1.2_1.2.5-2ubuntu0.7.04.1.diff.gz
Size/MD5:12496 b7fab5d4c24566e0b6687c4f1965d356
http://security.ubuntu.com/ubuntu/poo...dl-image1.2_1.2.5-2ubuntu0.7.04.1.dsc
Size/MD5:799 1164a9560c489027b5f7c35c0ff88940
http://security.ubuntu.com/ubuntu/poo...age1.2/sdl-image1.2_1.2.5.orig.tar.gz
Size/MD5:1308637 cd006109a73bf7dcc93e1c3ed15ee782

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...2-dev_1.2.5-2ubuntu0.7.04.1_amd64.deb
Size/MD5:38086 3865a5c45b1f93f85093d497605978da
http://security.ubuntu.com/ubuntu/poo...ge1.2_1.2.5-2ubuntu0.7.04.1_amd64.deb
Size/MD5:31678 6ffdff8cd099fa61bbd642010855470b

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo....2-dev_1.2.5-2ubuntu0.7.04.1_i386.deb
Size/MD5:34636 1101c9993d3bd36dce2b30d49c13e735
http://security.ubuntu.com/ubuntu/poo...age1.2_1.2.5-2ubuntu0.7.04.1_i386.deb
Size/MD5:29846 e45ba5dbe02a80dabfe2bfe9a14eb0de

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...dev_1.2.5-2ubuntu0.7.04.1_powerpc.deb
Size/MD5:39218 3a9de5d81673a486dcd67422b04cba3d
http://security.ubuntu.com/ubuntu/poo...1.2_1.2.5-2ubuntu0.7.04.1_powerpc.deb
Size/MD5:34488 a99d88e2c4f4be1bf9b54a4408b6da9f

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...2-dev_1.2.5-2ubuntu0.7.04.1_sparc.deb
Size/MD5:36304 7800adda592b293e5b3bddba909765d1
http://security.ubuntu.com/ubuntu/poo...ge1.2_1.2.5-2ubuntu0.7.04.1_sparc.deb
Size/MD5:30212 94bffe0f402269e7d697c5c2a42ab8ec

-- Ubuntu 7.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...sdl-image1.2_1.2.5-3ubuntu0.1.diff.gz
Size/MD5:27013 918b44bd4851bc05e539d0b4462da7aa
http://security.ubuntu.com/ubuntu/poo...1.2/sdl-image1.2_1.2.5-3ubuntu0.1.dsc
Size/MD5:789 e8c98a5eba6615818895b7c7df91e294
http://security.ubuntu.com/ubuntu/poo...age1.2/sdl-image1.2_1.2.5.orig.tar.gz
Size/MD5:1308637 cd006109a73bf7dcc93e1c3ed15ee782

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...age1.2-dev_1.2.5-3ubuntu0.1_amd64.deb
Size/MD5:38238 d972ea754a2ad5267e861fbfbc685ffb
http://security.ubuntu.com/ubuntu/poo...l-image1.2_1.2.5-3ubuntu0.1_amd64.deb
Size/MD5:31760 cf98987b70c07bf213d872db9de38d48

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...mage1.2-dev_1.2.5-3ubuntu0.1_i386.deb
Size/MD5:34732 6302e8d01dbdb7abcbf73c3b29da4260
http://security.ubuntu.com/ubuntu/poo...dl-image1.2_1.2.5-3ubuntu0.1_i386.deb
Size/MD5:29892 c9dab7a7643a65e78b2abfe56074679e

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...e1.2-dev_1.2.5-3ubuntu0.1_powerpc.deb
Size/MD5:39326 79e6eca19a9b299fa6889125705371e7
http://security.ubuntu.com/ubuntu/poo...image1.2_1.2.5-3ubuntu0.1_powerpc.deb
Size/MD5:34546 9c67ead459d5ac24e3851e7aca6f1771

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...age1.2-dev_1.2.5-3ubuntu0.1_sparc.deb
Size/MD5:36364 5dc30616c96abfaf72bf409bca419f83
http://security.ubuntu.com/ubuntu/poo...l-image1.2_1.2.5-3ubuntu0.1_sparc.deb
Size/MD5:30324 a04f1db06575cd845bab268ce7231264

Original Advisory:
http://www.ubuntu.com/usn/usn-595-1

Other References:
SA28640:
http://secunia.com/advisories/28640/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

287 Related Secunia Security Advisories, displaying 10

1. Ubuntu update for vorbis-tools
2. Ubuntu update for gst-plugins-good0.10
3. Ubuntu update for kdelibs
4. Ubuntu update for emacs
5. Ubuntu update for thunderbird
6. Ubuntu update for speex
7. Ubuntu update for openoffice.org
8. Ubuntu update for ldm
9. Ubuntu update for cups
10. Ubuntu update for firefox

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
SAP Internet Transaction Server wgate.dll Cross-Site Scripting Vulnerability
2.
Yahoo! Assistant yNotifier.dll ActiveX Control Code Execution
3.
Slackware update for thunderbird
4.
Cyberfolio "rep" File Inclusion Vulnerability
5.
Zarafa Script Insertion Vulnerabilities
6.
Ubuntu update for vorbis-tools
7.
Ubuntu update for gst-plugins-goo d0.10
8.
OpenKM Document Export Security Issue
9.
vShare YouTube Clone "tid" SQL Injection Vulnerability
10.
TFTP Server SP Long Error Message Buffer Overflow





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia