CVE-2016-6352
Publication date 27 July 2016
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
Status
Package | Ubuntu Release | Status |
---|---|---|
gdk-pixbuf | ||
16.04 LTS xenial |
Fixed 2.32.2-1ubuntu1.2
|
|
14.04 LTS trusty |
Fixed 2.30.7-0ubuntu1.6
|
|
Notes
sbeattie
gdk-pixbuf report notes that this may not be necessary for precise, as the reproducer doesn't crash with 2.26. Also, patch does not apply cleanly to precise's 2.26.1 version.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3085-1
- GDK-PixBuf vulnerabilities
- 21 September 2016