First published: Mon Oct 03 2016(Updated: )
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
gdk-pixbuf | <=2.35.2 | |
SUSE Linux | =42.1 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6352 is classified as a high severity vulnerability due to its potential for causing denial of service.
To fix CVE-2016-6352, upgrade gdk-pixbuf to version 2.35.3 or later.
CVE-2016-6352 affects Ubuntu Linux versions 12.04, 14.04, 16.04 and gdk-pixbuf versions up to 2.35.2.
CVE-2016-6352 allows remote attackers to execute a denial of service attack by exploiting out-of-bounds write errors.
Yes, CVE-2016-6352 can be exploited by remote attackers without the need for authentication.