Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gdk-pixbuf | Gnome | * | 2.36.12 (excluding) |
Gdk-pixbuf | Ubuntu | artful | * |
Gdk-pixbuf | Ubuntu | precise | * |
Gdk-pixbuf | Ubuntu | trusty | * |
Gdk-pixbuf | Ubuntu | upstream | * |
Gdk-pixbuf | Ubuntu | vivid/stable-phone-overlay | * |
Gdk-pixbuf | Ubuntu | xenial | * |
Gdk-pixbuf | Ubuntu | yakkety | * |
Gdk-pixbuf | Ubuntu | zesty | * |