8.8
CVSSv3

CVE-2017-1000422

Published: 02/01/2018 Updated: 02/05/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdk-pixbuf

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 7.0

canonical ubuntu linux 17.10

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

Vendor Advisories

Several security issues were fixed in GDK-PixBuf ...
It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened For the oldstable distribution (jessie), this problem has been fixed in version 2311-2+deb8u7 For the stable distribution (stretch ...