CVE Vulnerabilities

CVE-2004-0782

Published: Oct 20, 2004 | Modified: Aug 11, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

Affected Software

Name Vendor Start Version End Version
Gdkpixbuf Gnome 0.17 (including) 0.17 (including)
Gdkpixbuf Gnome 0.18 (including) 0.18 (including)
Gdkpixbuf Gnome 0.20 (including) 0.20 (including)
Gdkpixbuf Gnome 0.22 (including) 0.22 (including)
Gtk Gnome 2.0.2 (including) 2.0.2 (including)
Gtk Gnome 2.0.6 (including) 2.0.6 (including)
Gtk Gnome 2.2.1 (including) 2.2.1 (including)
Gtk Gnome 2.2.3 (including) 2.2.3 (including)
Gtk Gnome 2.2.4 (including) 2.2.4 (including)
Red Hat Enterprise Linux 3 RedHat gdk-pixbuf-1:0.22.0-11.3.3 *
Red Hat Enterprise Linux 3 RedHat gtk2-0:2.2.4-8.1 *
Gdk-pixbuf Ubuntu dapper *
Gdk-pixbuf Ubuntu devel *
Gdk-pixbuf Ubuntu edgy *
Gdk-pixbuf Ubuntu feisty *
Gtk+2.0 Ubuntu dapper *
Gtk+2.0 Ubuntu devel *
Gtk+2.0 Ubuntu edgy *
Gtk+2.0 Ubuntu feisty *

References