CVE Vulnerabilities

CVE-2004-0782

Published: Oct 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

Affected Software

NameVendorStart VersionEnd Version
GdkpixbufGnome0.17 (including)0.17 (including)
GdkpixbufGnome0.18 (including)0.18 (including)
GdkpixbufGnome0.20 (including)0.20 (including)
GdkpixbufGnome0.22 (including)0.22 (including)
GtkGnome2.0.2 (including)2.0.2 (including)
GtkGnome2.0.6 (including)2.0.6 (including)
GtkGnome2.2.1 (including)2.2.1 (including)
GtkGnome2.2.3 (including)2.2.3 (including)
GtkGnome2.2.4 (including)2.2.4 (including)
Red Hat Enterprise Linux 3RedHatgdk-pixbuf-1:0.22.0-11.3.3*
Red Hat Enterprise Linux 3RedHatgtk2-0:2.2.4-8.1*
Gdk-pixbufUbuntudapper*
Gdk-pixbufUbuntudevel*
Gdk-pixbufUbuntuedgy*
Gdk-pixbufUbuntufeisty*
Gtk+2.0Ubuntudapper*
Gtk+2.0Ubuntudevel*
Gtk+2.0Ubuntuedgy*
Gtk+2.0Ubuntufeisty*

References