First published: Fri Nov 18 2005(Updated: )
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GdkPixbuf | ||
GTK | <2.8.7 | |
GTK+ | =2.2.3 | |
GTK+ | =2.0.2 | |
GTK+ | =2.0.8 | |
GTK+ | =1.2.8 | |
GTK+ | =2.0.4 | |
GTK+ | =2.0.9 | |
GTK+ | ||
GTK+ | =2.4.0 | |
GTK+ | =2.2.4 | |
GTK+ | =2.0.1 | |
GTK+ | =2.0.3 | |
GTK+ | =2.0.7 | |
GTK+ | =2.0.6 | |
GTK+ | =2.2.1 | |
GTK+ | =2.0.18 | |
GTK+ | =2.0.0 | |
GTK+ | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2975 is considered a denial of service vulnerability due to an infinite loop caused by a crafted XPM image.
To fix CVE-2005-2975, upgrade to GdkPixbuf version after 2.8.7 or apply the appropriate patches provided by your distribution.
CVE-2005-2975 affects various versions of GTK+ and the GdkPixbuf library prior to version 2.8.7.
To mitigate CVE-2005-2975, avoid opening untrusted XPM images and ensure software is kept up to date.
CVE-2005-2975 enables a denial of service attack by causing applications to enter an infinite loop when processing malicious XPM images.