Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gtk+2.0 | Jul 30, 2024 | Oct 20, 2004 |
| Freebsd | — | Upgrade gtkUpgrade gdk-pixbufUpgrade linux-gdk-pixbuf | Dec 10, 2025 | Sep 15, 2004 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Oct 20, 2004 |
| Suse | — | Upgrade gtk2Upgrade gdk-pixbufUpgrade gtk2-devel-64bitUpgrade gdk-pixbuf-gnomeUpgrade gdk-pixbuf-x86Upgrade gtk2-32bitUpgrade gdk-pixbuf-develUpgrade gtk2-x86Upgrade gtk2-develUpgrade gtk2-64bit | Feb 17, 2015 | Oct 20, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub