CVE Vulnerabilities

CVE-2015-4491

Published: Aug 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

Affected Software

NameVendorStart VersionEnd Version
Gdk-pixbufGnome*2.31.4 (including)
Red Hat Enterprise Linux 5RedHatfirefox-0:38.2.0-4.el5_11*
Red Hat Enterprise Linux 5RedHatthunderbird-0:38.2.0-4.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:38.2.0-4.el6_7*
Red Hat Enterprise Linux 6RedHatthunderbird-0:38.2.0-4.el6_7*
Red Hat Enterprise Linux 6RedHatgdk-pixbuf2-0:2.24.1-6.el6_7*
Red Hat Enterprise Linux 7RedHatfirefox-0:38.2.0-4.el7_1*
Red Hat Enterprise Linux 7RedHatthunderbird-0:38.2.0-1.el7_1*
Red Hat Enterprise Linux 7RedHatgdk-pixbuf2-0:2.28.2-5.ael7b_1*
FirefoxUbuntudevel*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuvivid*
Gdk-pixbufUbuntudevel*
Gdk-pixbufUbuntuprecise*
Gdk-pixbufUbuntutrusty*
Gdk-pixbufUbuntuupstream*
Gdk-pixbufUbuntuvivid*
Gdk-pixbufUbuntuvivid/stable-phone-overlay*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuprecise*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuvivid*

References