Описание
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
Отчет
Red Hat Product Security has rated this issue as having Moderate security impact. A fix is available upstream in gdk-pixbuf master; a release containing the fix is pending.
Меры по смягчению последствий
Avoid opening or automatically indexing untrusted JPEG images with applications linked against a vulnerable gdk-pixbuf version until an updated package is installed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gdk-pixbuf2 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | glycin-loaders | Not affected | ||
| Red Hat Enterprise Linux 10 | loupe | Not affected | ||
| Red Hat Enterprise Linux 10 | snapshot | Not affected | ||
| Red Hat Enterprise Linux 6 | gdk-pixbuf2 | Not affected | ||
| Red Hat Enterprise Linux 7 | gdk-pixbuf2 | Fix deferred | ||
| Red Hat Enterprise Linux 8 | gdk-pixbuf2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | gdk-pixbuf2 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG ...
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
EPSS
4.7 Medium
CVSS3