CVE Vulnerabilities

CVE-2005-3186

Published: Nov 18, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Gdkpixbuf Gnome * *
Gtk+ Gtk 2.4.0 (including) 2.4.0 (including)
Red Hat Enterprise Linux 3 RedHat gdk-pixbuf-1:0.22.0-13.el3.3 *
Red Hat Enterprise Linux 3 RedHat gtk2-0:2.2.4-19 *
Red Hat Enterprise Linux 4 RedHat gdk-pixbuf-1:0.22.0-17.el4.3 *
Red Hat Enterprise Linux 4 RedHat gtk2-0:2.4.13-18 *
Gdk-pixbuf Ubuntu dapper *
Gdk-pixbuf Ubuntu devel *
Gdk-pixbuf Ubuntu edgy *
Gdk-pixbuf Ubuntu feisty *
Gtk+2.0 Ubuntu dapper *
Gtk+2.0 Ubuntu devel *
Gtk+2.0 Ubuntu edgy *
Gtk+2.0 Ubuntu feisty *

References