{"affected":[{"ecosystem_specific":{"binaries":[{"gtk2-devel":"2.18.9-0.45.8.1","gtk2-devel-32bit":"2.18.9-0.45.8.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"gtk2","purl":"pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.9-0.45.8.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"gtk2":"2.18.9-0.45.8.1","gtk2-32bit":"2.18.9-0.45.8.1","gtk2-doc":"2.18.9-0.45.8.1","gtk2-lang":"2.18.9-0.45.8.1","gtk2-x86":"2.18.9-0.45.8.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"gtk2","purl":"pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.9-0.45.8.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"gtk2":"2.18.9-0.45.8.1","gtk2-32bit":"2.18.9-0.45.8.1","gtk2-doc":"2.18.9-0.45.8.1","gtk2-lang":"2.18.9-0.45.8.1","gtk2-x86":"2.18.9-0.45.8.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"gtk2","purl":"pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.9-0.45.8.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for gtk2 provides the following fixes:\n\nThese security issues were fixed:\n\n- CVE-2017-6312: Prevent integer overflow that allowed context-dependent\n  attackers to cause a denial of service (segmentation fault and application\n  crash) via a crafted image entry offset in an ICO file (bsc#1027026).\n- CVE-2017-6314: The make_available_at_least function allowed context-dependent\n  attackers to cause a denial of service (infinite loop) via a large TIFF file\n  (bsc#1027025).\n- CVE-2017-6313: Prevent integer underflow in the load_resources function that\n  allowed context-dependent attackers to cause a denial of service (out-of-bounds\n  read and program crash) via a crafted image entry size in an ICO file\n  (bsc#1027024).\n- CVE-2017-2862: Prevent heap overflow in the\n  gdk_pixbuf__jpeg_image_load_increment function. A specially crafted jpeg file\n  could have caused a heap overflow resulting in remote code execution\n  (bsc#1048289)\n- CVE-2017-2870: Prevent integer overflow in the tiff_image_parse\n  functionality. A specially crafted tiff file could have caused a heap-overflow\n  resulting in remote code execution (bsc#1048544).\n\nThis non-security issue was fixed:\n\n- Prevent an infinite loop when a window is destroyed while traversed (bsc#1039465).\n","id":"SUSE-SU-2018:2470-1","modified":"2018-08-21T12:55:58Z","published":"2018-08-21T12:55:58Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182470-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1039465"},{"type":"REPORT","url":"https://bugzilla.suse.com/1048289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1048544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6314"}],"related":["CVE-2017-2862","CVE-2017-2870","CVE-2017-6312","CVE-2017-6313","CVE-2017-6314"],"summary":"Security update for gtk2","upstream":["CVE-2017-2862","CVE-2017-2870","CVE-2017-6312","CVE-2017-6313","CVE-2017-6314"]}