REDHAT-BUG-2377063: Medium severity Gnome GDK-PixBuf vulnerability
Heap‑buffer‑overflow vulnerability in the JPEG and Base64 decoding paths of gdk‑pixbuf. The flaw occurs in gdkpixbufjpegimageloadincrement() (io‑jpeg.c:1193:26) when a specially crafted JPEG triggers a flow that leads to gbase64encodestep() in glib (gbase64.c:141:16), reading beyond heap buffer bounds. Exploitation requires no authentication and could lead to application crash or arbitrary code execution via crafted images.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2377063?
The severity of REDHAT-BUG-2377063 is categorized as critical due to the potential for remote code execution.
How do I fix REDHAT-BUG-2377063?
To fix REDHAT-BUG-2377063, update gdk-pixbuf and GLib to their latest patched versions.
What software does REDHAT-BUG-2377063 affect?
REDHAT-BUG-2377063 affects gdk-pixbuf and GLib.
What is the nature of the vulnerability in REDHAT-BUG-2377063?
The vulnerability in REDHAT-BUG-2377063 is a heap-buffer overflow that occurs during JPEG and Base64 decoding.
Can REDHAT-BUG-2377063 be exploited remotely?
Yes, REDHAT-BUG-2377063 can be exploited remotely if a user processes a specially crafted JPEG image.