First published: Tue Jul 03 2012(Updated: )
The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME gdk-pixbuf | <=2.23.3 | |
GNOME gdk-pixbuf | =2.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-2485 is categorized as moderate due to its potential to cause denial of service.
To fix CVE-2011-2485, upgrade gdk-pixbuf to version 2.23.5 or later.
CVE-2011-2485 allows remote attackers to execute denial of service attacks through specifically crafted GIF image files.
Versions of gdk-pixbuf prior to 2.23.5, including 2.22.1, are affected by CVE-2011-2485.
There are no known workarounds for CVE-2011-2485 other than upgrading to the fixed version.