io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gdk-pixbuf | Aug 30, 2017 | Oct 26, 2015 |
| Debian | — | Upgrade gtk+2.0Upgrade gdk-pixbuf | Nov 9, 2015 | Oct 24, 2015 |
| Freebsd | — | Upgrade gdk-pixbuf2 | Dec 10, 2025 | Oct 5, 2015 |
| Gentoo Linux | — | Upgrade x11-libs/gdk-pixbuf. | Oct 30, 2017 | Oct 26, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 1, 2015 |
| Suse | — | Upgrade libgdk_pixbuf-2_0-0-32bitUpgrade gdk-pixbuf-thumbnailerUpgrade typelib-1_0-GdkPixdata-2_0Upgrade gdk-pixbuf-query-loadersUpgrade libgdk_pixbuf-2_0-0Upgrade typelib-1_0-GdkPixbuf-2_0Upgrade gdk-pixbuf-query-loaders-32bitUpgrade gdk-pixbuf-langUpgrade gdk-pixbuf-devel | Dec 18, 2015 | Oct 26, 2015 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Nov 8, 2024 | Oct 26, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub