6.8
CVSSv2

CVE-2015-7674

Published: 26/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf prior to 2.32.1 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 15.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

gnome gdk-pixbuf

opensuse opensuse 13.2

Vendor Advisories

GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file ...
Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-7673 Gustavo Grieco discovered a heap overflow in the processing of TGA images which may result in the execution of arbitrary cod ...
Integer overflow in the pixops_scale_nearest function in pixops/pixopsc in gdk-pixbuf before 2321 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow ...