CVE-2004-0788: Integer Overflow
Published Sep 17, 2004
·Updated
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
Affected Software
10 affected components
Gnome GdkPixbuf=0.17
Gnome GdkPixbuf=0.18
Gnome GdkPixbuf=0.20
Gnome GdkPixbuf=0.22
Gnome GTK>=2.0.0<2.2.4
GTK Gtk\+=2.2.3
GTK Gtk\+=2.0.2
GTK Gtk\+=2.2.4
GTK Gtk\+=2.0.6
GTK Gtk\+=2.2.1
Remediation
Patch Available
Patch Available
Event History
Sep 17, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0788?
CVE-2004-0788 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2004-0788?
To fix CVE-2004-0788, upgrade gdk-pixbuf to version 0.22 or later and gtk/gtk+ to version 2.2.4 or later.
3
Which software is affected by CVE-2004-0788?
CVE-2004-0788 affects gdk-pixbuf versions 0.17 through 0.22 and gtk/gtk+ versions 2.0.0 through 2.2.4.
4
What type of attack does CVE-2004-0788 facilitate?
CVE-2004-0788 can be exploited by remote attackers to carry out denial of service attacks.
5
Is CVE-2004-0788 a local or remote vulnerability?
CVE-2004-0788 is considered a remote vulnerability as it can be triggered by crafted ICO files sent over a network.