CVE-2004-0782Improper Restriction of Operations within the Bounds of a Memory Buffer in Gdkpixbuf

8 documents7 sources
Severity
7.5HIGHNVD
EPSS
30.0%
top 3.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 20
Latest updateApr 29

Description

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debiangnome/gdk-pixbuf< 0.22.0-7+3
NVDgnome/gdkpixbuf4 versions+3
NVDgnome/gtk5 versions+4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g6wq-qgq2-g3hg: Integer overflow in pixbuf_create_from_xpm (io-xpm2022-04-29
OSV
CVE-2004-0782: Integer overflow in pixbuf_create_from_xpm (io-xpm2004-10-20
CVEList
CVE-2004-0782: Integer overflow in pixbuf_create_from_xpm (io-xpm2004-09-17

📋Vendor Advisories

2
Red Hat
security flaw2004-09-15
Debian
CVE-2004-0782: gdk-pixbuf - Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder f...2004

💬Community

1
Bugzilla
CVE-2004-0782 security flaw2018-08-16
CVE-2004-0782 — Gnome Gdkpixbuf vulnerability | cvebase