First published: Wed Mar 20 2019(Updated: )
It was discovered that the GDK-PixBuf library did not properly handle certain BMP images. If an user or automated system were tricked into opening a specially crafted BMP file, a remote attacker could use this flaw to cause GDK-PixBuf to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libgdk-pixbuf2.0-0 | <2.32.2-1ubuntu1.6 | 2.32.2-1ubuntu1.6 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this GDK-PixBuf vulnerability is CVE-2017-12447.
The severity of USN-3912-1 is not specified.
If an user or automated system opens a specially crafted BMP file, it could cause GDK-PixBuf to crash, resulting in a denial of service or possibly remote code execution.
The version of libgdk-pixbuf2.0-0 affected by this vulnerability is up to but not including version 2.32.2-1ubuntu1.6.
To fix the GDK-PixBuf vulnerability, update the libgdk-pixbuf2.0-0 package to version 2.32.2-1ubuntu1.6 or later.