An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbuf | Dec 23, 2019 | Sep 5, 2017 |
| Freebsd | — | Upgrade gtk-pixbuf2 | Sep 2, 2017 | Sep 1, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade gdk-pixbuf2Upgrade gdk-pixbuf2-devel | Feb 13, 2018 | Sep 5, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gdk-pixbuf2Upgrade gdk-pixbuf2-devel | Feb 13, 2018 | Sep 5, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 7, 2016 |
| Suse | — | Upgrade gdk-pixbuf-query-loadersUpgrade typelib-1_0-GdkPixdata-2_0Upgrade gtk2Upgrade gdk-pixbuf-query-loaders-32bitUpgrade libgdk_pixbuf-2_0-0-32bitUpgrade gdk-pixbuf-develUpgrade typelib-1_0-GdkPixbuf-2_0Upgrade gtk2-docUpgrade gdk-pixbuf-langUpgrade gdk-pixbuf-thumbnailerUpgrade libgdk_pixbuf-2_0-0Upgrade gtk2-langUpgrade gtk2-x86Upgrade gtk2-32bitUpgrade gtk2-devel-32bitUpgrade gtk2-devel | Sep 6, 2017 | Aug 30, 2017 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Sep 18, 2017 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub