Out-of-bounds Write
Affecting gdk-pixbuf package, versions <2.31.1-2+deb8u8
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2016-6352
- CWE
- CWE-787
- Snyk ID
- SNYK-DEBIAN8-GDKPIXBUF-345002
- Disclosed
- 03 Oct, 2016
- Published
- 03 Oct, 2016