CVE-2012-2370

Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gdk-pixbuf:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.23.3:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.23.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.23.5:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.24.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.24.1:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.25.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdk-pixbuf:2.25.2:*:*:*:*:*:*:*

History

13 Feb 2023, 04:33

Type Values Removed Values Added
Summary CVE-2012-2370 gdk-pixbuf: DoS (GLib error and application abort) due to an integer overflow in the XBM image file format loader Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=822468', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=822468', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2013:0135', 'name': 'https://access.redhat.com/errata/RHSA-2013:0135', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2012-2370', 'name': 'https://access.redhat.com/security/cve/CVE-2012-2370', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:15

Type Values Removed Values Added
Summary Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow. CVE-2012-2370 gdk-pixbuf: DoS (GLib error and application abort) due to an integer overflow in the XBM image file format loader
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=822468 -
  • (MISC) https://access.redhat.com/errata/RHSA-2013:0135 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2012-2370 -

Information

Published : 2012-08-13 20:55

Updated : 2023-12-10 11:16


NVD link : CVE-2012-2370

Mitre link : CVE-2012-2370

CVE.ORG link : CVE-2012-2370


JSON object : View

Products Affected

gnome

  • gdk-pixbuf
CWE
CWE-189

Numeric Errors