The Windows versions of dvdisaster 0.70.x/0.72.x are shipped with an outdated
GTK library containing vulnerabilities in its image processing routines.
To exploit the vulnerability, manipulated images need to be loaded from
an external source. Since dvdisaster does not contain/use such functions,
these vulnerabilities are not considered to be a threat.
It is not recommended to replace GTK in the 0.70.x/0.72.x versions of
dvdisaster as some interfaces have been changed in newer GTK versions.
Replacing GTK will likely cause severe malfunction.
The windows version of dvdisaster 0.73.1 will have updated interfaces
and will be shipped with a current version of GTK.
Many thanks to all users who brought this issue to my attention.
|