Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-7345

Опубликовано: 08 июл. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.

Отчет

The Red Hat Product Security team has rated this vulnerability as Moderate.The flaw, identified in gdk-pixbuf, allows remote attackers to trigger a denial of service by supplying a specially crafted image file. This issue stems from improper bounds handling during image decoding. While exploitable without authentication, it does not lead to data compromise or code execution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gdk-pixbuf2Out of support scope
Red Hat Enterprise Linux 10gdk-pixbuf2FixedRHSA-2025:1286205.08.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportgdk-pixbuf2FixedRHSA-2025:1468326.08.2025
Red Hat Enterprise Linux 8gdk-pixbuf2FixedRHSA-2025:1331507.08.2025
Red Hat Enterprise Linux 8gdk-pixbuf2FixedRHSA-2025:1331507.08.2025
Red Hat Enterprise Linux 8.2 Advanced Update Supportgdk-pixbuf2FixedRHSA-2025:1461826.08.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportgdk-pixbuf2FixedRHSA-2025:1464726.08.2025
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Ongdk-pixbuf2FixedRHSA-2025:1464726.08.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportgdk-pixbuf2FixedRHSA-2025:1464626.08.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicegdk-pixbuf2FixedRHSA-2025:1464626.08.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2377063gdk‑pixbuf: Heap‑buffer‑overflow in gdk‑pixbuf

EPSS

Процентиль: 33%
0.00129
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.

CVSS3: 7.5
nvd
2 месяца назад

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.

CVSS3: 7.5
msrc
2 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
2 месяца назад

A flaw exists in gdk\u2011pixbuf within the gdk_pixbuf__jpeg_image_loa ...

suse-cvrf
20 дней назад

Security update for gdk-pixbuf

EPSS

Процентиль: 33%
0.00129
Низкий

7.5 High

CVSS3