io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbufUpgrade gtk+2.0 | Jul 30, 2024 | Nov 18, 2005 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Nov 18, 2005 |
| Suse | — | Upgrade gtk2-develUpgrade gdk-pixbuf-x86Upgrade gtk2-devel-64bitUpgrade gdk-pixbufUpgrade gdk-pixbuf-devel | Feb 17, 2015 | Nov 18, 2005 |
| Ubuntu | — | Upgrade libgdk-pixbuf2 | Nov 8, 2024 | Nov 18, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub