PT-2005-5562 · Gtk++1 · Gtk++1

Infamous41Md

·

Published

1970-01-01

·

Updated

2023-08-03

·

CVE-2005-3186

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GTK+ version 2.4.0 GTK+ versions prior to 2.8.6-r1
Description The issue is related to an integer overflow in the GTK+ gdk-pixbuf XPM image rendering library, which can lead to a heap-based buffer overflow, allowing attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated. Multiple vulnerabilities in various packages, including gdk-pixbuf-gnome, gtk2, gdk-pixbuf-devel, libgtk-common, libgtk2.0-dbg, gtk2-devel, and gtk2-doc, can be exploited remotely, leading to disruption of protected information.
Recommendations For GTK+ version 2.4.0, update to a version later than 2.4.0 to resolve the issue. For GTK+ versions prior to 2.8.6-r1, update to version 2.8.6-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to XPM files to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-01416
BDU:2015-01418
BDU:2015-04235
BDU:2015-04236
BDU:2015-04237
BDU:2015-04238
BDU:2015-06097
BDU:2015-06098
BDU:2015-06099
BDU:2015-09481
CVE-2005-3186
DSA-911-1
DSA-913-1
RHSA-2005:810
RHSA-2005:811
RHSA-2005_810
RHSA-2005_811

Affected Products

Gtk+
Red Hat