5

CVE-2012-2370

Exploit

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
GnomeGdk-pixbuf Version <= 2.26.0
GnomeGdk-pixbuf Version2.23.3
GnomeGdk-pixbuf Version2.23.4
GnomeGdk-pixbuf Version2.23.5
GnomeGdk-pixbuf Version2.24.0
GnomeGdk-pixbuf Version2.24.1
GnomeGdk-pixbuf Version2.25.0
GnomeGdk-pixbuf Version2.25.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.27% 0.84
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P