First published: Wed Feb 17 2016(Updated: )
Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, which triggers a large memory allocation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.10 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7447 has a moderate severity level as it can cause a denial of service by crashing applications handling large image files.
To fix CVE-2013-7447, it is recommended to update GTK+ to version 3.9.8 or later.
CVE-2013-7447 affects applications including eom, gnome-photos, eog, gambas3, thunar, and pinpoint.
Vulnerable platforms include Ubuntu Linux versions 12.04, 14.04, and 15.10.
Yes, CVE-2013-7447 can be exploited remotely through the use of specially crafted large image files.