Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gtk+2.0Upgrade gdk-pixbuf | Jul 30, 2024 | Nov 18, 2005 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Nov 18, 2005 |
| Suse | — | Upgrade gtk2-x86Upgrade gtk2Upgrade gtk2-develUpgrade gdk-pixbufUpgrade gtk2-32bitUpgrade gdk-pixbuf-x86Upgrade gdk-pixbuf-develUpgrade gtk2-64bit | Feb 17, 2015 | Nov 18, 2005 |
| Ubuntu | — | Upgrade libgdk-pixbuf2 | Nov 8, 2024 | Nov 18, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub