CVE-2015-7673: Buffer Overflow
Published Oct 26, 2015
·Updated
io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.
Affected Software
2 affected components
openSUSE openSUSE=13.2
Gnome GDK-PixBuf<=2.31.4
Remediation
Patch Available
Event History
Oct 26, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7673?
CVE-2015-7673 has a high severity rating due to its potential to cause a denial of service and arbitrary code execution.
2
How do I fix CVE-2015-7673?
The recommended fix for CVE-2015-7673 is to update gdk-pixbuf to version 2.32.0 or later.
3
Which versions of gdk-pixbuf are affected by CVE-2015-7673?
CVE-2015-7673 affects gdk-pixbuf versions up to and including 2.31.4.
4
Can CVE-2015-7673 be exploited remotely?
Yes, CVE-2015-7673 can be exploited remotely via a crafted Truevision TGA file.
5
What kind of vulnerabilities does CVE-2015-7673 represent?
CVE-2015-7673 represents a heap-based buffer overflow vulnerability.