CVE-2017-6314: Medium severity Gnome GDK-PixBuf vulnerability
Last updated 25 August 2025
Other sources
The makeavailableatleast function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gdk-pixbufto a version that resolves this vulnerability.Fixed in 2.42.2+dfsg-1+deb11u2Fixed in 2.42.2+dfsg-1+deb11u4Fixed in 2.42.10+dfsg-1+deb12u3Fixed in 2.42.10+dfsg-1+deb12u2Fixed in 2.42.12+dfsg-4Fixed in 2.44.5+dfsg-4
Event History
Frequently Asked Questions
What is CVE-2017-6314?
CVE-2017-6314 is a vulnerability in gdk-pixbuf that allows context-dependent attackers to cause a denial of service via a large TIFF file.
Which software is affected by CVE-2017-6314?
The GNOME gdk-pixbuf version up to and excluding 2.36.12, Fedora 30 and 31, Debian Linux 8.0, and certain versions of Ubuntu gdk-pixbuf are affected by CVE-2017-6314.
What is the severity of CVE-2017-6314?
CVE-2017-6314 has a severity rating of medium with a CVSSv3 score of 5.5.
How can the CVE-2017-6314 vulnerability be fixed?
To fix the CVE-2017-6314 vulnerability, update gdk-pixbuf to version 2.36.12 or later, Fedora to a version after 31, Debian Linux to a version after 8.0, or Ubuntu gdk-pixbuf to the specified remedied version.
Where can I find more information about CVE-2017-6314?
You can find more information about CVE-2017-6314 at the following references: [1] [2] [3].