ELA-1201-1 gtk+3.0 security update

cwd module loading

2024-10-07
Packagegtk+3.0
Version3.14.5-1+deb8u2 (jessie), 3.22.11-1+deb9u1 (stretch), 3.24.5-1+deb10u1 (buster)
Related CVEs CVE-2024-6655


Modules were also searched in the current working directory in the GNOME toolkit gtk+3.0, allowing library injection.



For Debian 10 buster, these problems have been fixed in version 3.24.5-1+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 3.14.5-1+deb8u2.

For Debian 9 stretch, these problems have been fixed in version 3.22.11-1+deb9u1.

We recommend that you upgrade your gtk+3.0 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.