Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbufUpgrade gtk+2.0 | Jul 30, 2024 | Oct 20, 2004 |
| Freebsd | — | Upgrade gtkUpgrade gdk-pixbufUpgrade linux-gdk-pixbuf | Dec 10, 2025 | Sep 15, 2004 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Oct 20, 2004 |
| Suse | — | Upgrade gtk2-devel-64bitUpgrade gdk-pixbuf-x86Upgrade gdk-pixbuf-gnomeUpgrade gdk-pixbufUpgrade gtk2-32bitUpgrade gtk2Upgrade gtk2-64bitUpgrade gtk2-develUpgrade gtk2-x86Upgrade gdk-pixbuf-devel | Feb 17, 2015 | Oct 20, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub