CVE-2015-7552
Published: April 18, 2016Last modified: November 9, 2023
Description
Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack Vector | LOCAL |
Attack complexity | LOW |
Privileges required | NONE |
User interaction | REQUIRED |
Scope | UNCHANGED |
Confidentiality | HIGH |
Integrity impact | HIGH |
Availability impact | HIGH |
Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | gdk-pixbuf | Not affected (2.42.10-r0) |
Stream | gdk-pixbuf | Not affected (2.42.10-r5) |
References
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00124.html
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00006.html
- http://www.debian.org/security/2016/dsa-3589
- http://www.ubuntu.com/usn/USN-3085-1
- https://bugzilla.suse.com/show_bug.cgi?id=958963
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJF5ARFOX4BFUK6YCBKGAKBQYECO3AI2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSAZ6UCKKXC5VOWXGWQHOX2ZBLLATIOT/