CVE-2017-6312: Integer Overflow
Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gdk-pixbufto a version that resolves this vulnerability.Fixed in 2.42.2+dfsg-1+deb11u2Fixed in 2.42.2+dfsg-1+deb11u4Fixed in 2.42.10+dfsg-1+deb12u3Fixed in 2.42.10+dfsg-1+deb12u2Fixed in 2.42.12+dfsg-4Fixed in 2.44.5+dfsg-4
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-6312.
What is the severity of CVE-2017-6312?
The severity of CVE-2017-6312 is medium with a CVSS score of 5.5.
Which software is affected by CVE-2017-6312?
The affected software includes GNOME gdk-pixbuf (up to version 2.36.12), Fedoraproject Fedora 30 and 31, Debian Debian Linux 8.0, and specific versions of Ubuntu gdk-pixbuf.
How can context-dependent attackers exploit CVE-2017-6312?
Context-dependent attackers can cause a denial of service by triggering an out-of-bounds read via a crafted image entry offset in an ICO file, leading to a segmentation fault and application crash.
Are there any fixes available for CVE-2017-6312?
Yes, there are fixes available for CVE-2017-6312. Users should update to the patched versions of the affected software.