ELA-1202-1 gtk+2.0 security update

cwd module loading

2024-10-07
Packagegtk+2.0
Version2.24.25-3+deb8u3 (jessie), 2.24.31-2+deb9u1 (stretch), 2.24.32-3+deb10u1 (buster)
Related CVEs CVE-2024-6655


Modules were also searched in the current working directory in the GNOME toolkit gtk+2.0, allowing library injection.



For Debian 10 buster, these problems have been fixed in version 2.24.32-3+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 2.24.25-3+deb8u3.

For Debian 9 stretch, these problems have been fixed in version 2.24.31-2+deb9u1.

We recommend that you upgrade your gtk+2.0 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.