CVE-2016-6352: High severity ubuntu vulnerability
Published Oct 3, 2016
·Updated
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
Affected Software
6 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Gnome GDK-PixBuf<=2.35.2
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Event History
Oct 3, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6352?
CVE-2016-6352 is classified as a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2016-6352?
To fix CVE-2016-6352, upgrade gdk-pixbuf to version 2.35.3 or later.
3
What systems are affected by CVE-2016-6352?
CVE-2016-6352 affects Ubuntu Linux versions 12.04, 14.04, 16.04 and gdk-pixbuf versions up to 2.35.2.
4
What type of attack does CVE-2016-6352 facilitate?
CVE-2016-6352 allows remote attackers to execute a denial of service attack by exploiting out-of-bounds write errors.
5
Can CVE-2016-6352 be exploited without authentication?
Yes, CVE-2016-6352 can be exploited by remote attackers without the need for authentication.