Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20326

Опубликовано: 19 янв. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

A heap-based buffer overflow was found in the way gThumb rendered certain JPEG images. An attacker could use a specially crafted JPEG image to cause gThumb to crash or execute arbitrary code with the permission of the user running gThumb.

Отчет

The vulnerable code was introduced in gthumb 2.13.2. Therefore the versions of gthumb package shipped with Red Hat Enterprise Linux 5 and 6 are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gthumbNot affected
Red Hat Enterprise Linux 6gthumbNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1794132gthumb: heap-based buffer overflow in _cairo_image_surface_create_from_jpeg in extensions/cairo_io/cairo-image-surface-jpeg.c

EPSS

Процентиль: 88%
0.03961
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
nvd
почти 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
debian
почти 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg( ...

EPSS

Процентиль: 88%
0.03961
Низкий

7.8 High

CVSS3