CVE-2004-0783: Buffer Overflow
Stack-based buffer overflow in xpmextractcolor (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0783?
CVE-2004-0783 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2004-0783?
To fix CVE-2004-0783, upgrade to a patched version of GTK+ or gdk-pixbuf that addresses the buffer overflow issue.
Which versions are affected by CVE-2004-0783?
CVE-2004-0783 affects GTK+ versions prior to 2.4.4 and gdk-pixbuf versions prior to 0.22.
Can CVE-2004-0783 be exploited remotely?
Yes, CVE-2004-0783 can be exploited remotely through specially crafted color strings.
What type of vulnerability is CVE-2004-0783?
CVE-2004-0783 is a stack-based buffer overflow vulnerability.