Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbuf | May 30, 2016 | Apr 18, 2016 |
| Suse | — | Upgrade gdk-pixbuf-query-loadersUpgrade gtk2-langUpgrade gdk-pixbuf-query-loaders-32bitUpgrade libgdk_pixbuf-2_0-0Upgrade gdk-pixbuf-langUpgrade gdk-pixbuf-develUpgrade gtk2-develUpgrade gtk2-devel-32bitUpgrade gtk2-x86Upgrade gtk2-32bitUpgrade gtk2-docUpgrade gdk-pixbuf-thumbnailerUpgrade gtk2Upgrade libgdk_pixbuf-2_0-0-32bitUpgrade typelib-1_0-GdkPixbuf-2_0Upgrade typelib-1_0-GdkPixdata-2_0 | Feb 2, 2016 | Jan 25, 2016 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Sep 21, 2016 | Apr 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub