Integer Overflow in gdk-pixbuf Affects GNOME Software
CVE-2017-6312

5.5MEDIUM

Key Information:

Vendor

Gnome

Vendor
CVE Published:
10 March 2017

What is CVE-2017-6312?

An integer overflow vulnerability in the io-ico.c component of gdk-pixbuf can be exploited by context-dependent attackers. By supplying a specially crafted ICO file with a malicious image entry offset, an attacker can trigger an out-of-bounds read, resulting in a segmentation fault and application crash. This issue is linked to specific compiler optimizations and requires careful handling of input to avoid denial of service.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.