Описание
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Отчет
This is a Low impact flaw as it requires a local attacker to provide a specially crafted ICNS file, leading to a denial of service or limited information disclosure. Exploitation necessitates user interaction to process the malicious file.
Меры по смягчению последствий
Do not open untrusted ICNS files from unknown sources. Disable ICNS image format support if not required.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gdk-pixbuf2 | Under investigation | ||
| Red Hat Enterprise Linux 10 | glycin-loaders | Under investigation | ||
| Red Hat Enterprise Linux 10 | gnome-tour | Under investigation | ||
| Red Hat Enterprise Linux 10 | librsvg2 | Under investigation | ||
| Red Hat Enterprise Linux 10 | loupe | Under investigation | ||
| Red Hat Enterprise Linux 10 | papers | Under investigation | ||
| Red Hat Enterprise Linux 10 | snapshot | Under investigation | ||
| Red Hat Enterprise Linux 6 | gdk-pixbuf2 | Under investigation | ||
| Red Hat Enterprise Linux 7 | gdk-pixbuf2 | Under investigation | ||
| Red Hat Enterprise Linux 8 | cppcheck | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block
A flaw was found in gdk-pixbuf. This vulnerability allows a remote att ...
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
EPSS
6.1 Medium
CVSS3