Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pr2-m366-8728

Опубликовано: 31 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.5
ubuntu
15 дней назад

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

CVSS3: 7.5
redhat
15 дней назад

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

CVSS3: 7.5
nvd
15 дней назад

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

CVSS3: 7.5
msrc
13 дней назад

Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image

CVSS3: 7.5
debian
15 дней назад

A flaw was found in the gdk-pixbuf library. This heap-based buffer ove ...

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-122