Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4491

Опубликовано: 11 авг. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

An integer overflow, leading to a heap-based buffer overflow, was found in the way gdk-pixbuf, an image loading library for GNOME, scaled certain bitmap format images. An attacker could use a specially crafted BMP image file that, when processed by an application compiled against the gdk-pixbuf library, would cause that application to crash or execute arbitrary code with the permissions of the user running the application.

Отчет

This issue did not affect the versions of gdk-pixbuf as shipped with Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdk-pixbufNot affected
Red Hat Enterprise Linux 5firefoxFixedRHSA-2015:158611.08.2015
Red Hat Enterprise Linux 5thunderbirdFixedRHSA-2015:168225.08.2015
Red Hat Enterprise Linux 6firefoxFixedRHSA-2015:158611.08.2015
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2015:168225.08.2015
Red Hat Enterprise Linux 6gdk-pixbuf2FixedRHSA-2015:169431.08.2015
Red Hat Enterprise Linux 7firefoxFixedRHSA-2015:158611.08.2015
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2015:168225.08.2015
Red Hat Enterprise Linux 7gdk-pixbuf2FixedRHSA-2015:169431.08.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1252290Mozilla: Heap overflow in gdk-pixbuf when scaling bitmap images (MFSA 2015-88)

EPSS

Процентиль: 90%
0.05713
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

nvd
около 10 лет назад

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

debian
около 10 лет назад

Integer overflow in the make_filter_table function in pixops/pixops.c ...

suse-cvrf
около 7 лет назад

Security update for gdk-pixbuf

suse-cvrf
около 7 лет назад

Security update for gdk-pixbuf

EPSS

Процентиль: 90%
0.05713
Низкий

6.8 Medium

CVSS2