Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.
2012-08-13T20:55:03.723
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnome | gdk-pixbuf | ≤ 2.26.0 | Yes |
Application | gnome | gdk-pixbuf | 2.23.3 | Yes |
Application | gnome | gdk-pixbuf | 2.23.4 | Yes |
Application | gnome | gdk-pixbuf | 2.23.5 | Yes |
Application | gnome | gdk-pixbuf | 2.24.0 | Yes |
Application | gnome | gdk-pixbuf | 2.24.1 | Yes |
Application | gnome | gdk-pixbuf | 2.25.0 | Yes |
Application | gnome | gdk-pixbuf | 2.25.2 | Yes |