A vulnerability have been discovered in the load function of the XPM
loader for imlib2, which allows attackers to cause a denial of service
(crash) and possibly execute arbitrary code via a crafted XPM file
(CVE-2008-5187).
The updated packages have been patched to prevent this.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-5187
_______________________________________________________________________