|
|
|
![]() |
Vulnerability Note VU#825374GdkPixbuf BMP parser may enter an infinite loopOverviewA vulnerability exists in the BMP handling of GdkPixbuf. This vulnerability can lead to a denial-of-service condition.I. DescriptionGdkPixbuf is a library used by GTK+ 2 for loading and rendering images. GTK+ is a multi-platform toolkit for creating graphical user interfaces. It is used by the Gnome desktop and other applications. GdkPixbuf contains a heap overflow vulnerability in the DoCompressed() function of the BMP loading routine.II. ImpactBy convincing the user to open a specially crafted BMP file, an attacker could cause a denial of service by crashing the application that uses GdkPixbuf.III. SolutionApply a patch from your vendorFor vendor-specific information regarding vulnerable status and patch availability, please see the vendor section of this document.
References
This vulnerability was reported by the Red Hat Security Response Team. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||