4.3
CVSSv2

CVE-2017-6314

Published: 10/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent malicious users to cause a denial of service (infinite loop) via a large TIFF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdk-pixbuf

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in GDK-PixBuf ...
Debian Bug report logs - #856444 gdk-pixbuf: CVE-2017-6312: Possible out-of-bounds read Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 05:57:02 UTC Severity ...
Debian Bug report logs - #856445 gdk-pixbuf: CVE-2017-6313: Integer underflow in io-icnsc Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 06:06:02 UTC Sever ...
Debian Bug report logs - #856448 gdk-pixbuf: CVE-2017-6314: Infinite loop in io-tiffc with large size Package: src:gdk-pixbuf; Maintainer for src:gdk-pixbuf is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 Mar 2017 06:09:0 ...
It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened For the oldstable distribution (jessie), this problem has been fixed in version 2311-2+deb8u7 For the stable distribution (stretch ...
The make_available_at_least function in io-tiffc in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file ...