Version: 2008
  • On The Insider: Britney's Bikini-Clad Top 10

December 8, 2004 2:48 PM PST

Linux groups patch image flaw

  • 18 comments
Several flaws in common Linux code used to process graphics in older versions of the GNOME desktop environment could allow an attacker to compromise a computer that displays a malicious image file, a security group warned this week.

The vulnerabilities occur in the Imlib software library, a set of common code for handling images, security information provider Secunia stated in an advisory Tuesday. The company rated the flaw threat as "highly critical."

Czech software developer Pavel Kankovsky discovered the flaws when he checked the Imlib library to see if it was affected by vulnerabilities found in a similar set of Linux code, Linux distributor Gentoo said in an advisory.

Both Gentoo and Novell's SuSE Linux released patches for the issue this week.

The image flaw is the latest graphics library vulnerability to affect a major operating system. Microsoft fixed a major flaw in how its operating system and applications handled the popular JPEG format. The flaw could be used to take control of a victim's PC by viewing a graphic. Another flaw in a popular code library for handling an open-source image format, known as Portable Network Graphics, put computers running Linux, Windows and Mac OS X at risk.

Another common element of Web pages, Sun Microsystems' Java, also had a major flaw that could affect Linux and Windows computer users. The company patched the issue in October.

Other versions of the Linux operating system are likely affected if they use an older version of the GNOME desktop. In addition, other applications on those systems could also be affected if that software uses the Imlib code.

See more CNET content tagged:
flaw, Gentoo, Linux, GNOME, vulnerability

Add a Comment (Log in or register) (18 Comments)
  • prev
  • 1
  • next
Hypocritical
by Andrew J Glina December 8, 2004 5:24 PM PST
If this was a story about a Windows flaw being fixed, no matter how fast, how minor it was or how well it was done, there would be a flood of comments from the Linux/Apple faithful. Maybe people are used to Linux being flawed so it isn?t worth commenting on.
Reply to this comment
Read my next comment related to this...
by Johnny Mnemonic December 8, 2004 5:38 PM PST
...
Looks like a Gnome vulnerability not Linux
by Johnny Mnemonic December 8, 2004 5:37 PM PST
I didn't see anything in the report that mentions
a Linux kernel flaw. The OS kernel generally doesn't
process images, so, I was a little confused when I
first read the title. It is like saying an Adobe
image library vulnerability is a Windows problem.
Not quite accurate. One can always develop an
application or library to circumvent the system,
it isn't necessarily the OS's fault.
Reply to this comment
Look at the facts, and stop creating another Holy War.
by Tex Murphy PI December 8, 2004 10:43 PM PST
KDE or GNOME - if it is a shell, it's still part of the OS.

I am amazed that MS came out with a fix to this vulnerability before the Linux community did!

I guess even MS can work quickly to fix a problem if you light enough matches under their feet! :)
View all 3 replies
I stand by my point
by Andrew J Glina December 9, 2004 5:56 AM PST
When was the last time that you heard of a security issue with the NT Kernel? Do you think that the NT Kernel handles images? I really don't see why you are mentioning Kernels. I didn't. Most of the problems of Windows are releated to the interface too. All software has it's problems, not just Microsofts. That was my point.
Reply to this comment
Thanks Andrew
by David Arbogast December 9, 2004 8:19 AM PST
A splash of reality is nice when zealots start preaching their faith.
View reply
problems of Windows
by George Cole June 16, 2007 1:36 PM PDT
http://www.analogstereo.com/kia_spectra_owners_manual.htm
Story incorrect, comments worse
by December 9, 2004 10:29 AM PST
Versions of GNOME in the 1.x series are affected by the imlib vulnerabilities discussed in this article, however, GNOME 1.x is not a "recent" version of GNOME by any stretch of the imagination. The 2.x series (which there have been four "minor" series of in the past two and a half years) does not use imlib, and the only distribution which continues to ship GNOME 1.x is debian woody (which will be replaced by sarge in a short while).

To compare GNOME 1.x and 2.x is roughly equivalent code-wise to comparing Windows NT4 to Windows 2000, or Windows 95 to Windows 3.1. Most of the code has been changed and rewritten, and all of the image handling (which this bug is an instance of) has. If you want a rough parallel, this is similar to discovering a bug that only occurs in Windows NT4 and claiming it affects "recent" versions of Windows.

I should note, regarding the comments, that this particular security issue was discovered as a result of independent code auditing by a random user of the imlib library--something that is legally impossible in the closed source world, unless you feel like paying money and signing all types of NDAs, which would almost certainly preclude disclosure of this type of vulnerability -- which means that even if somebody paid the money to see the code and found a vulnerability like this, you probably wouldn't hear about it until after an update is ready or someone *else* tests things the hard way and discovers the same issue independently. Further, unless you are doing something dumb, like running as the "root" user (Administrator in Windows NT/2k+/XP), this bug will only affect *your* user, and not the entire system. Finally, this issue has never been exploited (to my knowledge) "in the wild", merely in some guy's apartment.

James Cape
http://esco.mine.nu/
Reply to this comment
Article is not wrong
by David Arbogast December 9, 2004 12:21 PM PST
The article does in fact state that this vulnerabilty exists in older Gnome packages. Its in the first paragraph, so there is nothing wrong with the assessment.

Just like flaws in older versions of Windows give anti-MS folks a reason to flame the software company, flaws in older versions of Linux are likewise targets for criticism. Why? Because there is still an affected install base. The difference, is that each distributor of Linux is working to patch the problem, meaning that different distros have different security problems at any given time.

Sure... somebody found this flaw a few years after it was created, in their own home. Something that could not be done with code from a closed-source system. You are correct. Of course, it is only a matter of luck that the person was willing to report the flaw instead of exploiting it.
closed source world
by Ubber geek June 6, 2007 7:41 AM PDT
http://www.analogstereo.com/cassette_deck_nakamichi_bx_300.htm
(18 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-0.16%) -17.24 10,433.71
S&P 500 (-0.05%) -0.59 1,105.65
NASDAQ (-0.31%) -6.83 2,169.18
CNET TECH (-0.31%) -5.03 1,599.12
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right