// For flags

CVE-2012-2370

gdk-pixbuf: DoS (GLib error and application abort) due to an integer overflow in the XBM image file format loader

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.

Múltiples desbordamientos de enteros en la función read_bitmap_file_data de io-xbm.c en gdk-pixbuf antes de v2.26.1 permite a atacantes remotos causar una denegación de servicio (por caída de la aplicación) a través de un valor negativo en la (1) altura o (2) anchura en un archivo XBM, lo que provoca un desbordamiento de búfer basado en memoria dinámica (heap).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-04-19 CVE Reserved
  • 2012-06-24 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-09-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
<= 2.26.0
Search vendor "Gnome" for product "Gdk-pixbuf" and version " <= 2.26.0"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.23.3
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.23.3"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.23.4
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.23.4"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.23.5
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.23.5"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.24.0
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.24.0"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.24.1
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.24.1"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.25.0
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.25.0"
-
Affected
Gnome
Search vendor "Gnome"
Gdk-pixbuf
Search vendor "Gnome" for product "Gdk-pixbuf"
2.25.2
Search vendor "Gnome" for product "Gdk-pixbuf" and version "2.25.2"
-
Affected