<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for gdk-pixbuf</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:2195-2</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2015-12-23T13:20:49Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2015-12-23T13:20:49Z</InitialReleaseDate>
    <CurrentReleaseDate>2015-12-23T13:20:49Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for gdk-pixbuf</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">The gdk pixbuf library was updated to fix three security issues.

These security issues were fixed:
- CVE-2015-7673: Fix some more overflows scaling a gif (bsc#948791)
- CVE-2015-4491: Check for overflow before allocating memory when scaling (bsc#942801)
- CVE-2015-7673: Fix an overflow and DoS when scaling TGA files (bsc#948790).
- CVE-2015-7674: Fix overflow when scaling GIF files(bsc#948791).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-SLE-DESKTOP-12-SP1-2015-946,SUSE-SLE-SDK-12-SP1-2015-946,SUSE-SLE-SERVER-12-SP1-2015-946</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20152195-2/</URL>
      <Description>Link for SUSE-SU-2015:2195-2</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-December/001761.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:2195-2</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/942801</URL>
      <Description>SUSE Bug 942801</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/948790</URL>
      <Description>SUSE Bug 948790</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/948791</URL>
      <Description>SUSE Bug 948791</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-4491/</URL>
      <Description>SUSE CVE CVE-2015-4491 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-7673/</URL>
      <Description>SUSE CVE CVE-2015-7673 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-7674/</URL>
      <Description>SUSE CVE CVE-2015-7674 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1" CPE="cpe:/o:suse:sled:12:sp1">SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1" CPE="cpe:/o:suse:sles:12:sp1">SUSE Linux Enterprise Server 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1" CPE="cpe:/o:suse:sles_sap:12:sp1">SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1" CPE="cpe:/o:suse:sle-sdk:12:sp1">SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="gdk-pixbuf-lang-2.30.6-7.2">
      <FullProductName ProductID="gdk-pixbuf-lang-2.30.6-7.2">gdk-pixbuf-lang-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdk-pixbuf-query-loaders-2.30.6-7.2">
      <FullProductName ProductID="gdk-pixbuf-query-loaders-2.30.6-7.2">gdk-pixbuf-query-loaders-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdk-pixbuf-query-loaders-32bit-2.30.6-7.2">
      <FullProductName ProductID="gdk-pixbuf-query-loaders-32bit-2.30.6-7.2">gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgdk_pixbuf-2_0-0-2.30.6-7.2">
      <FullProductName ProductID="libgdk_pixbuf-2_0-0-2.30.6-7.2">libgdk_pixbuf-2_0-0-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2">
      <FullProductName ProductID="libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2">libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2">
      <FullProductName ProductID="typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2">typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdk-pixbuf-devel-2.30.6-7.2">
      <FullProductName ProductID="gdk-pixbuf-devel-2.30.6-7.2">gdk-pixbuf-devel-2.30.6-7.2</FullProductName>
    </Branch>
    <Relationship ProductReference="gdk-pixbuf-lang-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-lang-2.30.6-7.2">gdk-pixbuf-lang-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2">gdk-pixbuf-query-loaders-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2">gdk-pixbuf-query-loaders-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2">libgdk_pixbuf-2_0-0-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2">libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2">typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-lang-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-lang-2.30.6-7.2">gdk-pixbuf-lang-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2">gdk-pixbuf-query-loaders-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2">gdk-pixbuf-query-loaders-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2">libgdk_pixbuf-2_0-0-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2">libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2">typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-lang-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-lang-2.30.6-7.2">gdk-pixbuf-lang-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2">gdk-pixbuf-query-loaders-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-query-loaders-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2">gdk-pixbuf-query-loaders-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2">libgdk_pixbuf-2_0-0-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2">libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2">typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdk-pixbuf-devel-2.30.6-7.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:gdk-pixbuf-devel-2.30.6-7.2">gdk-pixbuf-devel-2.30.6-7.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.</Note>
    </Notes>
    <CVE>CVE-2015-4491</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:gdk-pixbuf-devel-2.30.6-7.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20152195-2/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-4491.html</URL>
        <Description>CVE-2015-4491</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/940806</URL>
        <Description>SUSE Bug 940806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/942801</URL>
        <Description>SUSE Bug 942801</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/948790</URL>
        <Description>SUSE Bug 948790</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.</Note>
    </Notes>
    <CVE>CVE-2015-7673</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:gdk-pixbuf-devel-2.30.6-7.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20152195-2/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-7673.html</URL>
        <Description>CVE-2015-7673</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/948790</URL>
        <Description>SUSE Bug 948790</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2015-7674</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-lang-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:gdk-pixbuf-query-loaders-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libgdk_pixbuf-2_0-0-32bit-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:typelib-1_0-GdkPixbuf-2_0-2.30.6-7.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:gdk-pixbuf-devel-2.30.6-7.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20152195-2/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-7674.html</URL>
        <Description>CVE-2015-7674</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/948791</URL>
        <Description>SUSE Bug 948791</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
