Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20326

Опубликовано: 19 янв. 2020
Источник: redhat
CVSS3: 7.8

Описание

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

A heap-based buffer overflow was found in the way gThumb rendered certain JPEG images. An attacker could use a specially crafted JPEG image to cause gThumb to crash or execute arbitrary code with the permission of the user running gThumb.

Отчет

The vulnerable code was introduced in gthumb 2.13.2. Therefore the versions of gthumb package shipped with Red Hat Enterprise Linux 5 and 6 are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gthumbNot affected
Red Hat Enterprise Linux 6gthumbNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1794132gthumb: heap-based buffer overflow in _cairo_image_surface_create_from_jpeg in extensions/cairo_io/cairo-image-surface-jpeg.c

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
nvd
больше 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
debian
больше 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg( ...

7.8 High

CVSS3