CVE-2011-2485Gdk-pixbuf vulnerability

9 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMay 17

Description

The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiangnome/gdk-pixbuf< 2.23.3-3.1+3
NVDgnome/gdk-pixbuf2.23.3+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5w8h-qwv6-rm5p: The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif2022-05-17
CVEList
CVE-2011-2485: The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif2012-07-03
OSV
CVE-2011-2485: The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif2012-07-03

📋Vendor Advisories

2
Red Hat
gdk-pixbuf: incorrect error detection in the GIF image loader2011-06-23
Debian
CVE-2011-2485: gdk-pixbuf - The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf bef...2011

💬Community

3
Bugzilla
CVE-2011-2485 gdk-pixbuf: Excessive memory use due improper checking of certain return values in GIF image loader [fedora-16]2011-06-24
Bugzilla
CVE-2011-2485 gdk-pixbuf: incorrect error detection in the GIF image loader2011-06-22
Bugzilla
pidgin: DoS (excessive memory consumption) by processing certain GIF images used as buddy icon2011-06-20
CVE-2011-2485 — Gnome Gdk-pixbuf vulnerability | cvebase