CVE-2017-2862: High severity gnome gdkpixbuf vulnerability
Published Sep 5, 2017
·Updated
An exploitable heap overflow vulnerability exists in the gdkpixbufjpegimageloadincrement functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability.
Affected Software
2 affected components
Gnome GDK-PixBuf=2.36.6
Debian Debian Linux=8.0
Event History
Sep 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2862?
CVE-2017-2862 has a severity score of 7.8, indicating a high level of risk.
2
How do I fix CVE-2017-2862?
To fix CVE-2017-2862, upgrade gdk-pixbuf to the latest available version that addresses this vulnerability.
3
What types of software are affected by CVE-2017-2862?
CVE-2017-2862 affects gdk-pixbuf version 2.36.6 and Debian Linux 8.0.
4
What are the implications of exploiting CVE-2017-2862?
Exploiting CVE-2017-2862 can lead to a heap overflow, which may allow remote code execution.
5
Can CVE-2017-2862 be triggered by a user action?
Yes, CVE-2017-2862 can be triggered by opening a specially crafted jpeg file or URL.