CVE-2012-2370

gdk-pixbuf < 2.26.1 - Denial of Service via Negative Height or Width in XBM File

Title source: llm
STIX 2.1

Description

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.

References (12)

Core 12
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-201206-20.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75578
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0135.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49125
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/15/9
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49715
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53548
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/15/8
Various Sources x_refsource_misc
http://git.gnome.org/browse/gdk-pixbuf/

Scores

EPSS 0.0227
EPSS Percentile 84.8%

Details

CWE
CWE-189
Status published
Products (8)
gnome/gdk-pixbuf 2.23.3
gnome/gdk-pixbuf 2.23.4
gnome/gdk-pixbuf 2.23.5
gnome/gdk-pixbuf 2.24.0
gnome/gdk-pixbuf 2.24.1
gnome/gdk-pixbuf 2.25.0
gnome/gdk-pixbuf 2.25.2
gnome/gdk-pixbuf < 2.26.0
Published Aug 13, 2012
Tracked Since Feb 18, 2026