Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6312

Опубликовано: 21 фев. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

An out-of-bounds read flaw was found in the way GdkPixbuf handled ICO format files. A maliciously crafted ICO file could cause the application using GdkPixbuf to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdk-pixbufWill not fix
Red Hat Enterprise Linux 6gdk-pixbuf2Will not fix
Red Hat Enterprise Linux 7gdk-pixbuf2Will not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1427221gdk-pixbuf: Out-of-bounds read in io-ico.c

EPSS

Процентиль: 54%
0.0031
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

CVSS3: 5.5
nvd
почти 9 лет назад

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

CVSS3: 5.5
debian
почти 9 лет назад

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent at ...

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

suse-cvrf
больше 8 лет назад

Security update for gdk-pixbuf

EPSS

Процентиль: 54%
0.0031
Низкий

3.3 Low

CVSS3