An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdk-pixbuf | Dec 23, 2019 | Sep 5, 2017 |
| Freebsd | — | Upgrade gtk-pixbuf2 | Sep 2, 2017 | Sep 1, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade gdk-pixbuf2Upgrade gdk-pixbuf2-devel | Feb 13, 2018 | Sep 5, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gdk-pixbuf2Upgrade gdk-pixbuf2-devel | Feb 13, 2018 | Sep 5, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 7, 2016 |
| Suse | — | Upgrade gtk2Upgrade gtk2-docUpgrade typelib-1_0-GdkPixdata-2_0Upgrade libgdk_pixbuf-2_0-0-32bitUpgrade typelib-1_0-GdkPixbuf-2_0Upgrade gdk-pixbuf-langUpgrade gdk-pixbuf-query-loaders-32bitUpgrade gdk-pixbuf-develUpgrade gdk-pixbuf-query-loadersUpgrade gtk2-langUpgrade gdk-pixbuf-thumbnailerUpgrade gtk2-devel-32bitUpgrade libgdk_pixbuf-2_0-0Upgrade gtk2-develUpgrade gtk2-32bitUpgrade gtk2-x86 | Sep 6, 2017 | Aug 30, 2017 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Sep 18, 2017 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub