After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 605310 - GTK+ 2.16.5.0 has security vulnerability, fixed in 2.18.5.0
GTK+ 2.16.5.0 has security vulnerability, fixed in 2.18.5.0
Status: RESOLVED INVALID
Product: GIMP
Classification: Other
Component: Windows Installer
2.6.7
Other Windows
: Normal normal
: ---
Assigned To: Jernej Simončič
Jernej Simončič
: 606319 (view as bug list)
Depends on:
Blocks:
 
 
Reported: 2009-12-23 15:07 UTC by MetaEd
Modified: 2010-01-07 16:42 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description MetaEd 2009-12-23 15:07:02 UTC
A patch has been released for GTK+ to close a security vulnerability. The oldest GTK+ release including the patch is 2.18.5.0. Recommend that GTK+ 2.18.5.0 or newer be bundled with GIMP.
Comment 1 Tor Lillqvist 2009-12-23 15:31:04 UTC
There are no "patches" that would be "released" for GTK+ sources. There are just releases. And the version number of the latest GTK+ source release is 2.18.5, there is no fourth number. Anyway, if you talk about the http://secunia.com/advisories/37852/ thing, that seems likely to be quite irrelevant on Windows. No need for scaremongering. If you have some concrete evidence to the contrary, please present them.
Comment 2 Tor Lillqvist 2009-12-23 15:39:51 UTC
Furthermore, the commit to GTK+ sources that is said to fix bug #598476 , which I guess is what you and the Secunia "advisiory" are talking about, affects the function gdk_window_begin_implicit_paint() in gdk/gdkwindow.c. That function and the whole implicit paint concept, as far as I understand, didn't even exist in GTK+ before 2.18.
Comment 3 MetaEd 2009-12-23 16:21:40 UTC
This comment did not appear when posted. I apologize if I am now creating a duplicate comment.

Secunia is reporting a security vulnerability in GIMP and all other software which bundle GTK+ older than 2.18.5. Thank you for figuring out and sharing that pre-2.18 GTK+ cannot have this vulnerability. I will communicate with Secunia and try to get them to acknowledge and correct their advisory.

The bug reporting guidelines explicitly say no bug is too small to report. Sorry if it was wrong to bring this to your attention --- perhaps the guidelines should be changed. If anyone is scaremongering, it is Secunia, so your scolding is perhaps misdirected.
Comment 4 Jernej Simončič 2010-01-07 16:42:46 UTC
*** Bug 606319 has been marked as a duplicate of this bug. ***