Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbufUpgrade gtk+2.0 | Jul 30, 2024 | Oct 20, 2004 |
| Freebsd | — | Upgrade gdk-pixbufUpgrade linux-gdk-pixbufUpgrade gtk | Dec 10, 2025 | Sep 15, 2004 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Oct 20, 2004 |
| Suse | — | Upgrade gdk-pixbuf-develUpgrade gtk2-64bitUpgrade gdk-pixbufUpgrade gtk2-devel-64bitUpgrade gtk2-32bitUpgrade gdk-pixbuf-gnomeUpgrade gtk2-develUpgrade gtk2-x86Upgrade gdk-pixbuf-x86Upgrade gtk2 | Feb 17, 2015 | Oct 20, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub