Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbuf | Jan 17, 2018 | Jan 2, 2018 |
| Gentoo Linux | — | Upgrade x11-libs/gdk-pixbuf. | Apr 18, 2018 | Jan 2, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade gdk-pixbuf2-develUpgrade gdk-pixbuf2 | Feb 13, 2018 | Jan 2, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gdk-pixbuf2-develUpgrade gdk-pixbuf2 | Feb 13, 2018 | Jan 2, 2018 |
| Suse | — | Upgrade gdk-pixbuf-query-loadersUpgrade libgdk_pixbuf-2_0-0-32bitUpgrade gdk-pixbuf-query-loaders-32bitUpgrade gdk-pixbuf-develUpgrade typelib-1_0-gdkpixbuf-2_0Upgrade libgdk_pixbuf-2_0-0Upgrade gdk-pixbuf-lang | Jul 17, 2018 | Jan 2, 2018 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Jan 16, 2018 | Jan 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub