6.8
CVSSv2

CVE-2015-7673

Published: 26/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

io-tga.c in gdk-pixbuf prior to 2.32.0 uses heap memory after its allocation failed, which allows remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

gnome gdk-pixbuf

Vendor Advisories

GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file ...
Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-7673 Gustavo Grieco discovered a heap overflow in the processing of TGA images which may result in the execution of arbitrary cod ...
io-tgac in gdk-pixbuf before 2320 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file ...