CVE-2005-2975: High severity Gnome GdkPixbuf vulnerability
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2975?
CVE-2005-2975 is considered a denial of service vulnerability due to an infinite loop caused by a crafted XPM image.
How do I fix CVE-2005-2975?
To fix CVE-2005-2975, upgrade to GdkPixbuf version after 2.8.7 or apply the appropriate patches provided by your distribution.
Which software is affected by CVE-2005-2975?
CVE-2005-2975 affects various versions of GTK+ and the GdkPixbuf library prior to version 2.8.7.
What precautions can I take against CVE-2005-2975?
To mitigate CVE-2005-2975, avoid opening untrusted XPM images and ensure software is kept up to date.
What type of attack does CVE-2005-2975 enable?
CVE-2005-2975 enables a denial of service attack by causing applications to enter an infinite loop when processing malicious XPM images.