Описание
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | libgxps | Not affected | ||
| Red Hat Enterprise Linux 7 | accountsservice | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | adwaita-icon-theme | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | appstream-data | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | atk | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | at-spi2-atk | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | at-spi2-core | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | baobab | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | bolt | Fixed | RHSA-2018:3140 | 30.10.2018 |
| Red Hat Enterprise Linux 7 | brasero | Fixed | RHSA-2018:3140 | 30.10.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
There is a stack-based buffer over-read in calling GLib in the functio ...
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
ELSA-2018-3140: GNOME security, bug fix, and enhancement update (MODERATE)
EPSS
3.3 Low
CVSS3