Debian Package Tracker
Register | Log in
Subscribe

gdk-pixbuf

Choose email to subscribe with

general
  • source: gdk-pixbuf (main)
  • version: 2.42.12+dfsg-4
  • maintainer: Debian GNOME Maintainers (archive) (DMD)
  • uploaders: Laurent Bigonville [DMD] – Emilio Pozuelo Monfort [DMD] – Iain Lane [DMD] – Jeremy Bicha [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.42.2+dfsg-1+deb11u2
  • old-sec: 2.42.2+dfsg-1+deb11u3
  • stable: 2.42.10+dfsg-1+deb12u1
  • stable-sec: 2.42.10+dfsg-1+deb12u2
  • stable-p-u: 2.42.10+dfsg-1+deb12u2
  • testing: 2.42.12+dfsg-3
  • unstable: 2.42.12+dfsg-4
versioned links
  • 2.42.2+dfsg-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.42.2+dfsg-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.42.10+dfsg-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.42.10+dfsg-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.42.12+dfsg-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.42.12+dfsg-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gdk-pixbuf-tests
  • gir1.2-gdkpixbuf-2.0
  • libgdk-pixbuf-2.0-0 (4 bugs: 1, 2, 1, 0)
  • libgdk-pixbuf-2.0-0-udeb
  • libgdk-pixbuf-2.0-dev
  • libgdk-pixbuf2.0-0-udeb
  • libgdk-pixbuf2.0-bin
  • libgdk-pixbuf2.0-common
  • libgdk-pixbuf2.0-doc
action needed
lintian reports 1 error and 3 warnings high
Lintian reports 1 error and 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-11-02 Last update: 2025-07-20 15:00
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-7345: A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.
Created: 2025-07-08 Last update: 2025-07-14 17:03
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2025-7345: A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.
Created: 2025-07-08 Last update: 2025-07-14 17:03
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2025-01-06 Last update: 2025-07-20 17:56
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.42.12+dfsg-5, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit a71060d1e5545a65feaf8a1ba4d6d6b284dc267f
Author: Simon McVittie <smcv@debian.org>
Date:   Mon Jul 14 12:29:56 2025 +0100

    Edit previous changelog entry to mention #1109262
Created: 2025-07-14 Last update: 2025-07-14 13:03
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2025-7345: (postponed; to be fixed through a stable update) A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-07-08 Last update: 2025-07-14 17:03
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-07-19 19:31
testing migrations
  • excuses:
    • Migration status for gdk-pixbuf (2.42.12+dfsg-3 to 2.42.12+dfsg-4): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating gdk-pixbuf would introduce bugs in testing: #1109199
    • ∙ ∙ blocked by freeze: is a key package (Follow the freeze policy when applying for an unblock)
    • ∙ ∙ Too young, only 7 of 20 days old
    • Additional info:
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/g/gdk-pixbuf.html
    • ∙ ∙ autopkgtest for gdk-pixbuf/2.42.12+dfsg-4: amd64: Pass, arm64: Pass, armel: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Reproducible on amd64 - info ♻
    • ∙ ∙ Waiting for reproducibility test results on armhf - info ♻
    • Not considered
news
[rss feed]
  • [2025-07-12] Accepted gdk-pixbuf 2.42.12+dfsg-4 (source) into unstable (Simon McVittie)
  • [2025-06-23] Accepted gdk-pixbuf 2.42.10+dfsg-1+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-06-23] Accepted gdk-pixbuf 2.42.2+dfsg-1+deb11u3 (source) into oldstable-security (Adrian Bunk)
  • [2025-06-23] gdk-pixbuf 2.42.12+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2025-06-22] Accepted gdk-pixbuf 2.42.10+dfsg-1+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-06-20] Accepted gdk-pixbuf 2.42.12+dfsg-3 (source) into unstable (Simon McVittie)
  • [2025-01-26] gdk-pixbuf 2.42.12+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-22] Accepted gdk-pixbuf 2.42.12+dfsg-2 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-06-22] Accepted gdk-pixbuf 2.42.2+dfsg-1+deb11u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2024-06-22] Accepted gdk-pixbuf 2.42.10+dfsg-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2024-05-19] gdk-pixbuf 2.42.12+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-16] Accepted gdk-pixbuf 2.42.12+dfsg-1 (source) into unstable (Simon McVittie)
  • [2023-11-19] gdk-pixbuf 2.42.10+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2023-11-14] Accepted gdk-pixbuf 2.42.10+dfsg-3 (source) into unstable (Simon McVittie)
  • [2023-11-08] gdk-pixbuf 2.42.10+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-02] Accepted gdk-pixbuf 2.42.10+dfsg-2 (source) into unstable (Simon McVittie)
  • [2022-11-21] gdk-pixbuf 2.42.10+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-18] Accepted gdk-pixbuf 2.42.10+dfsg-1 (source) into unstable (Simon McVittie)
  • [2022-09-17] Accepted gdk-pixbuf 2.42.2+dfsg-1+deb11u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2022-09-11] Accepted gdk-pixbuf 2.42.2+dfsg-1+deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2022-08-20] gdk-pixbuf 2.42.9+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-16] Accepted gdk-pixbuf 2.42.9+dfsg-1 (source) into unstable (Simon McVittie)
  • [2022-07-30] gdk-pixbuf 2.42.8+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2022-07-27] Accepted gdk-pixbuf 2.42.8+dfsg-2 (source) into unstable (Sebastien Bacher)
  • [2022-03-31] gdk-pixbuf 2.42.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-28] Accepted gdk-pixbuf 2.42.8+dfsg-1 (source) into unstable (Jeremy Bicha)
  • [2021-08-21] gdk-pixbuf 2.42.6+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2021-08-15] Accepted gdk-pixbuf 2.42.6+dfsg-2 (source) into unstable (Simon McVittie)
  • [2021-06-02] Accepted gdk-pixbuf 2.42.6+dfsg-1 (source) into experimental (Simon McVittie)
  • [2020-12-18] gdk-pixbuf 2.42.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 24 31
  • RC: 1
  • I&N: 20 27
  • M&W: 3
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (1, 3)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (-, 83)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.42.12+dfsg-3
  • 51 bugs (3 patches)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing