CVE-2005-3186

gdkpixbuf - Integer Overflow and Heap-Based Buffer Overflow via XPM Image Rendering

Title source: manual
STIX 2.1

Description

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

References (30)

Core 30
Core References
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_65_gtk2.html
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=339&type=vulnerabilities
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200511-14.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15435
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17710
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18509
Third Party Advisory, VDB Entry vendor-advisory x_refsource_fedora
http://www.securityfocus.com/archive/1/428052/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-911
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17562
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17615
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-811.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17522
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2433
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-913
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17538
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/188
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-216-1
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214
Various Sources vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.8/SCOSA-2006.8.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015216
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17591
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17770
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17594
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17588
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9503
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17592
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17791
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17657
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-810.html

Scores

EPSS 0.0222
EPSS Percentile 84.7%

Details

Status published
Products (2)
gnome/gdkpixbuf
gtk/gtk\+ 2.4.0
Published Nov 18, 2005
Tracked Since Feb 18, 2026