Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-0783


Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).


Published

2004-10-20T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnome gdkpixbuf 0.17 Yes
Application gnome gdkpixbuf 0.18 Yes
Application gnome gdkpixbuf 0.20 Yes
Application gnome gdkpixbuf 0.22 Yes
Application gnome gtk 2.0.2 Yes
Application gnome gtk 2.0.6 Yes
Application gnome gtk 2.2.1 Yes
Application gnome gtk 2.2.3 Yes
Application gnome gtk 2.2.4 Yes

References