PT-2005-5560 · Gtk++4 · Gtk2+12

Ludwig Nussel

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2005-2975

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions gdk-pixbuf-gnome versions 0.22.0 gtk2 versions prior to 2.8.7 gdk-pixbuf-devel versions 0.22.0 libgtk-common (affected versions not specified) gtk2 (affected versions not specified) gdk-pixbuf versions 0.22.0 libgtk2.0-dbg (affected versions not specified) gtk2-devel (affected versions not specified) gtk2-doc (affected versions not specified) gtk+ versions prior to 2.8.7
Description The issue is related to multiple vulnerabilities in various packages of different Linux operating systems, including Red Hat Enterprise Linux, SUSE Linux Enterprise, Debian GNU/Linux, and Gentoo Linux. These vulnerabilities can be exploited remotely and may lead to a denial of service, causing disruption to the availability of protected information. Specifically, the io-xpm.c file in the gdk-pixbuf XPM image rendering library in GTK+ before version 2.8.7 allows attackers to cause a denial of service via a crafted XPM image with a large number of colors.
Recommendations For gdk-pixbuf-gnome version 0.22.0, update to a version later than 0.22.0. For gtk2 versions prior to 2.8.7, update to version 2.8.7 or later. For gdk-pixbuf-devel version 0.22.0, update to a version later than 0.22.0. For libgtk-common, update to the latest available version. For gtk2, update to the latest available version. For gdk-pixbuf version 0.22.0, update to a version later than 0.22.0. For libgtk2.0-dbg, update to the latest available version. For gtk2-devel, update to the latest available version. For gtk2-doc, update to the latest available version. For gtk+ versions prior to 2.8.7, update to version 2.8.7 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01416
BDU:2015-01418
BDU:2015-04235
BDU:2015-04236
BDU:2015-04237
BDU:2015-04238
BDU:2015-06097
BDU:2015-06098
BDU:2015-06099
BDU:2015-09481
CVE-2005-2975
DSA-911-1
DSA-913-1
OPENSUSE-SU-2024:10834-1
RHSA-2005:810
RHSA-2005:811
RHSA-2005_810
RHSA-2005_811

Affected Products

Debian
Gentoo Linux
Red Hat
Suse Linux Enterprise
Gdk-Pixbuf
Gdk-Pixbuf-Devel
Gdk-Pixbuf-Gnome
Gtk+
Gtk2
Gtk2-Devel
Gtk2-Doc
Libgtk-Common
Libgtk2.0-Dbg