Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gtk+2.0Upgrade gdk-pixbuf | Jul 30, 2024 | Nov 18, 2005 |
| Gentoo Linux | — | Upgrade media-libs/gdk-pixbuf.Upgrade x11-libs/gtk+. | Oct 30, 2017 | Nov 18, 2005 |
| Suse | — | Upgrade gtk2Upgrade gtk2-32bitUpgrade gtk2-64bitUpgrade gdk-pixbufUpgrade gdk-pixbuf-x86Upgrade gtk2-develUpgrade gtk2-x86Upgrade gdk-pixbuf-devel | Feb 17, 2015 | Nov 18, 2005 |
| Ubuntu | — | Upgrade libgdk-pixbuf2 | Nov 8, 2024 | Nov 18, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub