PT-2018-5197 · Gnome+3 · Gdk-Pixbuf+3

Jun

·

Published

2017-08-21

·

Updated

2019-05-02

·

CVE-2017-1000422

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gnome gdk-pixbuf versions 2.36.8 and older
Description The issue is related to several integer overflows in the gif get lzw function, which can result in memory corruption and potentially allow code execution.
Recommendations For versions 2.36.8 and older, update to a newer version to mitigate the risk of exploitation. At the moment, there is no information about a specific newer version that contains a fix for this issue.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2087
CVE-2017-1000422
DLA-1234-1
DSA-4088-1
MGASA-2018-0087
MGASA-2018-0090
OPENSUSE-SU-2018_2013-1
SUSE-SU-2018:1950-1
SUSE-SU-2018_1950-1
USN-3532-1

Affected Products

Alt Linux
Suse
Ubuntu
Gdk-Pixbuf