PT-2019-6074 · Gnome+4 · Gdk-Pixbuf+4
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gdk-pixbuf versions prior to 2.42.0
Description
A flaw in gdk-pixbuf can cause an integer wraparound leading to an out of bounds write when a crafted GIF image is loaded. This may allow an attacker to crash applications or potentially execute code on the victim system, posing a threat to data confidentiality and integrity as well as system availability.
Recommendations
For versions prior to 2.42.0, update to version 2.42.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted GIF images until a patch is applied. Restrict access to sensitive data and systems to minimize the risk of exploitation.
Correção
Integer Underflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linuxmint
Red Os
Ubuntu
Gdk-Pixbuf