ELA-1151-1 gdk-pixbuf security update

ANI memory corruption

2024-08-13
Packagegdk-pixbuf
Version2.31.1-2+deb8u10 (jessie), 2.36.5-2+deb9u3 (stretch), 2.38.1+dfsg-1+deb10u1 (buster)
Related CVEs CVE-2022-48622


Memory corruption has been fixed in the loader for ANI (animated cursors) files in GDK Pixbuf, a library used by the GTK widget toolkit.



For Debian 10 buster, these problems have been fixed in version 2.38.1+dfsg-1+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 2.31.1-2+deb8u10.

For Debian 9 stretch, these problems have been fixed in version 2.36.5-2+deb9u3.

We recommend that you upgrade your gdk-pixbuf packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.