PT-2012-1128 · Gnome+1 · Gdk-Pixbuf+1

Publicado

2012-06-23

·

Atualizado

2024-06-15

·

CVE-2011-2485

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions gdk-pixbuf versions prior to 2.23.5 gdk-pixbuf versions prior to 2.24.1-r1
Description The issue is related to the gdk pixbuf gif image load function in gdk-pixbuf/io-gif.c, which does not properly handle certain return values. This allows remote attackers to cause a denial of service, specifically memory consumption, via a crafted GIF image file. Multiple vulnerabilities in the gdk-pixbuf package can lead to disruption of protected information availability, and exploitation can be done remotely.
Recommendations For versions prior to 2.23.5, update to version 2.23.5 or later. For versions prior to 2.24.1-r1, update to version 2.24.1-r1 or later. As a temporary workaround, consider restricting the use of the gdk pixbuf gif image load function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09656
CVE-2011-2485
OPENSUSE-SU-2024:10453-1
SUSE-SU-2012_0841-1
SUSE-SU-2012_0844-1

Produtos afetados

Suse
Gdk-Pixbuf