Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade imlib2 | Jul 30, 2024 | Jan 10, 2005 |
| Freebsd | — | Upgrade imlibUpgrade imlib2 | Dec 10, 2025 | Jan 21, 2005 |
| Gentoo Linux | — | Upgrade media-libs/imlib.Upgrade media-libs/imlib2. | Oct 30, 2017 | Jan 10, 2005 |
| Suse | — | Upgrade imlibUpgrade imlib-x86Upgrade imlib-32bitUpgrade imlib-64bitUpgrade imlib-devel | Dec 12, 2013 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub