PT-2007-7473 · Gtk++1 · Gtk2+1

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-0010

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions gtk2 versions prior to 2.4.13
Description The issue is related to multiple vulnerabilities in the gtk2 package, which can lead to a denial of service (crash) when a malformed image file is processed by the GdkPixbufLoader function. This can be exploited by a local attacker, potentially disrupting the availability of protected information.
Recommendations For versions prior to 2.4.13, update to version 2.4.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the GdkPixbufLoader function until a patch is available. Avoid processing untrusted or malformed image files with the affected function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01410
BDU:2015-01411
BDU:2015-01412
BDU:2015-01413
BDU:2015-01414
BDU:2015-01415
BDU:2015-01417
CVE-2007-0010
DSA-1256-1
OPENSUSE-SU-2024:10834-1
RHSA-2007:0019
RHSA-2007_0019

Affected Products

Red Hat
Gtk2