REDHAT-BUG-2506437: Medium severity gdk-pixbuf vulnerability
A flaw was found in gdk-pixbuf, affecting all versions. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This issue causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap contents via the generated output, such as a thumbnail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2506437?
The severity of REDHAT-BUG-2506437 is medium, rated as a 4.
How do I fix REDHAT-BUG-2506437?
To resolve REDHAT-BUG-2506437, update gdk-pixbuf to the latest version that addresses this vulnerability.
What software is affected by REDHAT-BUG-2506437?
The affected software for REDHAT-BUG-2506437 is gdk-pixbuf, impacting all versions.
What type of vulnerability is REDHAT-BUG-2506437?
REDHAT-BUG-2506437 is a flaw related to improper bounds checking when parsing specially crafted ICO files.
What potential impact does REDHAT-BUG-2506437 have?
The potential impact of REDHAT-BUG-2506437 includes out-of-bounds reads leading to heap memory interpretation issues.