Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbufUpgrade gtk+2.0 | Jul 30, 2024 | Nov 18, 2005 |
| Gentoo Linux | — | Upgrade x11-libs/gtk+.Upgrade media-libs/gdk-pixbuf. | Oct 30, 2017 | Nov 18, 2005 |
| Suse | — | Upgrade gdk-pixbuf-develUpgrade gtk2-64bitUpgrade gtk2-32bitUpgrade gdk-pixbufUpgrade gdk-pixbuf-x86Upgrade gtk2-develUpgrade gtk2-x86Upgrade gtk2 | Feb 17, 2015 | Nov 18, 2005 |
| Ubuntu | — | Upgrade libgdk-pixbuf2 | Nov 8, 2024 | Nov 18, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub