Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:03010-1

Опубликовано: 28 авг. 2025
Источник: suse-cvrf

Описание

Security update for gdk-pixbuf

This update for gdk-pixbuf fixes the following issues:

  • CVE-2025-7345: Fixed heap buffer overflow in gdk_pixbuf__jpeg_image_load_increment function (bsc#1246114)

Список пакетов

Image SLES12-SP5-Azure-SAP-BYOS
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-Azure-SAP-On-Demand
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-EC2-SAP-BYOS
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-EC2-SAP-On-Demand
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-GCE-SAP-BYOS
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-GCE-SAP-On-Demand
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
gdk-pixbuf-query-loaders-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
SUSE Linux Enterprise Server 12 SP5-LTSS
gdk-pixbuf-devel-2.34.0-19.23.1
gdk-pixbuf-lang-2.34.0-19.23.1
gdk-pixbuf-query-loaders-2.34.0-19.23.1
gdk-pixbuf-query-loaders-32bit-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-32bit-2.34.0-19.23.1
typelib-1_0-GdkPixbuf-2_0-2.34.0-19.23.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
gdk-pixbuf-devel-2.34.0-19.23.1
gdk-pixbuf-lang-2.34.0-19.23.1
gdk-pixbuf-query-loaders-2.34.0-19.23.1
gdk-pixbuf-query-loaders-32bit-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-2.34.0-19.23.1
libgdk_pixbuf-2_0-0-32bit-2.34.0-19.23.1
typelib-1_0-GdkPixbuf-2_0-2.34.0-19.23.1

Описание

A flaw exists in gdk-pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib's g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.


Затронутые продукты
Image SLES12-SP5-Azure-SAP-BYOS:gdk-pixbuf-query-loaders-2.34.0-19.23.1
Image SLES12-SP5-Azure-SAP-BYOS:libgdk_pixbuf-2_0-0-2.34.0-19.23.1
Image SLES12-SP5-Azure-SAP-On-Demand:gdk-pixbuf-query-loaders-2.34.0-19.23.1
Image SLES12-SP5-Azure-SAP-On-Demand:libgdk_pixbuf-2_0-0-2.34.0-19.23.1

Ссылки
Уязвимость SUSE-SU-2025:03010-1