On CBSSports.com: Watch Championship Games Online
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Dec 8, 2004 10:48:00 PM

Several flaws in common Linux code used to process graphics in older versions of the GNOME desktop environment could allow an attacker to compromise a computer that displays a malicious image file, a security group warned this week.

The vulnerabilities occur in the Imlib software library, a set of common code for handling images, security information provider Secunia stated in an advisory Tuesday. The company rated the flaw threat as "highly critical."

Czech software developer Pavel Kankovsky discovered the flaws when he checked the Imlib library to see if it was affected by vulnerabilities found in a similar set of Linux code, Linux distributor Gentoo said in an advisory.

Both Gentoo and Novell's SuSE Linux released patches for the issue this week.

The image flaw is the latest graphics library vulnerability to affect a major operating system. Microsoft fixed a major flaw in how its operating system and applications handled the popular JPEG format. The flaw could be used to take control of a victim's PC by viewing a graphic. Another flaw in a popular code library for handling an open-source image format, known as Portable Network Graphics, put computers running Linux, Windows and Mac OS X at risk.

Another common element of Web pages, Sun Microsystems' Java, also had a major flaw that could affect Linux and Windows computer users. The company patched the issue in October.

Other versions of the Linux operating system are likely affected if they use an older version of the GNOME desktop. In addition, other applications on those systems could also be affected if that software uses the Imlib code.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 33 Talkback(s)
Actually, you're wrong.
You linsux zealots crack me up. Can't stand the truth can you so you must make up lies.

Uh, no. I don't use Linux. I did install it on a non-networked PC to try it out, and while it wa... (Read the rest)
Posted by: James T. Kirk Posted on: 12/10/04 You are currently: a Guest | | Terms of Use
Linux User  richdave | 12/08/04
Hmmm  Linux User 147560 | 12/08/04
According to www.gentoo-portage.com...  Michael Kelly | 12/08/04
Patched before exploit?  computer_man | 12/09/04
Really?  Linux User 147560 | 12/09/04
There is no virus or trojan  computer_man | 12/09/04
Proves Nothing  Roger Ramjet | 12/09/04
Cursed Zealots  nucrash | 12/09/04
Two things  PA-ITGuy | 12/09/04
Two things, yes  Roger Ramjet | 12/09/04
Not much gain  PA-ITGuy | 12/09/04
Besides, there are counter measures.  nucrash | 12/09/04
Correct, Lindoze by nature is much more secure  FilledOut | 12/09/04
I'm glad I read this  Michael Kelly | 12/08/04
Isn't this old news?  hani_y | 12/08/04
Linux groups patch image flaw  Loverock Davidson | 12/09/04
Nothing to see here folks, just an MS shill. Move along, move it along..  James T. Kirk | 12/09/04
HAHHAHA!  Loverock Davidson | 12/09/04
Mike Cox was better  nucrash | 12/09/04
Actually, you're wrong.  James T. Kirk | 12/10/04
And yet...  Michael Kelly | 12/09/04
Yes  Loverock Davidson | 12/09/04
No, you and you alone go around bashing  Monkey_MCSE | 12/09/04
This is an A-B conversation C your way out of it! (NT)  Loverock Davidson | 12/09/04
D-fine your role please?  nucrash | 12/09/04
I guess being called out  Monkey_MCSE | 12/09/04
free?  nucrash | 12/09/04
FreeBSD has the answer  nucrash | 12/09/04
you cant speak for everyone  doh123 | 12/09/04
OMG... A linux flaw  nucrash | 12/09/04
More info?  SC-man | 12/09/04
PS is true, but....  nucrash | 12/09/04
doesnt look like a linux flaw to me...  doh123 | 12/09/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • lg cbs sports logo
  • It's March, and time once again for the ritual we call The Big Dance®. Our advice to business managers: Embrace it! Equip your conference room with the biggest TV that's practical for your space and make sure your users can stream March Madness on Demand from CBS Sports.com. That way they can watch every game from the first round of the NCAA Championship - online, on demand and for FREE! We say let them do it. It'll give your people something to cheer (or weep about) together.
  • small cbs sports logo