Logo
componentgdk-pixbuf
Name
gdk-pixbuf
Version
2.44.6
Type
library
Description
Image loading library for GTK+
Licenses
LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:gnome:gdk-pixbuf:2.44.6:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.42.10
scarthgap
2.42.12

Patches#


#
Title
Author
Resolve
1
gdk-pixbuf: add an option so that loader errors are fatal
Ross Burton <ross.burton@intel.com>
2
meson.build: allow (a subset of) tests in cross compile
Alexander Kanavin <alex@linutronix.de>

Vulnerabilities#


Name
Analysis
Description
Not Affected
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Exploitable
Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.
Exploitable
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.