7.1
CVSSv3

CVE-2017-6313

Published: 10/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent malicious users to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdk-pixbuf

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in GDK-PixBuf ...
It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened For the oldstable distribution (jessie), this problem has been fixed in version 2311-2+deb8u7 For the stable distribution (stretch ...
Debian Bug report logs - #856448 gdk-pixbuf: CVE-2017-6314: Infinite loop in io-tiffc with large size Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 06:09:0 ...
Debian Bug report logs - #856445 gdk-pixbuf: CVE-2017-6313: Integer underflow in io-icnsc Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 06:06:02 UTC Sever ...
Debian Bug report logs - #856444 gdk-pixbuf: CVE-2017-6312: Possible out-of-bounds read Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 05:57:02 UTC Severity ...
Integer underflow in the load_resources function in io-icnsc in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file ...