First published: Mon Oct 26 2015(Updated: )
Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.04 | |
gdk-pixbuf | <=2.32.0 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7674 is rated as a high severity vulnerability due to its potential to cause application crashes and execute arbitrary code.
To fix CVE-2015-7674, update gdk-pixbuf to version 2.32.1 or later as well as relevant packages on affected systems.
CVE-2015-7674 affects systems running versions of Ubuntu Linux 12.04, 14.04, 15.04, GNOME gdk-pixbuf up to 2.32.0, and openSUSE 13.2.
Exploiting CVE-2015-7674 could lead to application crashes and potentially allow attackers to execute arbitrary code remotely.
As of now, specific public exploits for CVE-2015-7674 have not been widely reported, but the vulnerability itself is serious enough to warrant caution.