6.8
CVSSv2

CVE-2019-20326

Published: 16/03/2020 Updated: 14/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb prior to 3.8.3 and Linux Mint Pix prior to 2.4.5 allows malicious users to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gthumb

linuxmint pix

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #948197 gthumb: CVE-2019-20326: Heap buffer overflow Package: src:gthumb; Maintainer for src:gthumb is Herbert Parentes Fortes Neto <hpfn@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 5 Jan 2020 08:33:01 UTC Severity: important Tags: fixed-upstream, security, ...
Several security issues were fixed in gThumb ...