Search CVE reports


Toggle filters

1 – 10 of 30 results


CVE-2022-48622

Medium priority

Some fixes available 6 of 7

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could...

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-46829

Medium priority
Fixed

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be...

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Not affected Fixed Not affected Not affected
Show less packages

CVE-2021-44648

Medium priority

Some fixes available 2 of 4

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed Fixed Not affected Not affected
Show less packages

CVE-2021-20240

Medium priority
Fixed

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially...

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed Not affected Not affected
Show less packages

CVE-2020-29385

Medium priority
Fixed

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next...

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed Not affected Not affected
Show less packages

CVE-2011-2897

Medium priority
Ignored

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf
Show less packages

CVE-2017-12447

Medium priority
Fixed

GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Not affected Fixed
Show less packages

CVE-2017-1000422

Medium priority

Some fixes available 2 of 3

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed
Show less packages

CVE-2017-2870

Medium priority
Fixed

An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution....

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed
Show less packages

CVE-2017-2862

Medium priority
Fixed

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An...

1 affected package

gdk-pixbuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gdk-pixbuf Fixed
Show less packages