Out-of-bounds read In gdk-pixbuf
Description
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 0.22.0-7 | ||
debian 12 | 2.4.9-2 | ||
debian 13 | 0.22.0-7 | ||
debian 14 | 0.22.0-7 | ||
debian 13 | 2.4.9-2 | ||
debian 14 | 2.4.9-2 | ||
debian 11 | 2.4.9-2 | ||
debian 12 | 0.22.0-7 |
Aliases
1. 2. 3. 4. 5.