Integer Underflow
Affecting gdk-pixbuf package, versions <2.36.5-2+deb9u2
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.
References
CVSS Score
7.1
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2017-6313
- CWE
- CWE-191
- Snyk ID
- SNYK-DEBIAN9-GDKPIXBUF-344957
- Disclosed
- 10 Mar, 2017
- Published
- 10 Mar, 2017