CVE Vulnerabilities

CVE-2004-0782

Published: Oct 20, 2004 | Modified: Aug 11, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

Affected Software

Name Vendor Start Version End Version
Gdkpixbuf Gnome 0.17 (including) 0.17 (including)
Gdkpixbuf Gnome 0.18 (including) 0.18 (including)
Gdkpixbuf Gnome 0.20 (including) 0.20 (including)
Gdkpixbuf Gnome 0.22 (including) 0.22 (including)
Gtk Gnome 2.0.2 (including) 2.0.2 (including)
Gtk Gnome 2.0.6 (including) 2.0.6 (including)
Gtk Gnome 2.2.1 (including) 2.2.1 (including)
Gtk Gnome 2.2.3 (including) 2.2.3 (including)
Gtk Gnome 2.2.4 (including) 2.2.4 (including)

References