Executive Summary
Summary | |
---|---|
Title | New gdk-pixbuf packages fix denial of service |
Informations | |||
---|---|---|---|
Name | DSA-464 | First vendor Publication | 2004-03-16 |
Vendor | Debian | Last vendor Modification | 2004-03-16 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Thomas Kristensen discovered a vulnerability in gdk-pixbuf (binary package libgdk-pixbuf2), the GdkPixBuf image library for Gtk, that can cause the surrounding application to crash. To exploit this problem, a remote attacker could send a carefully-crafted BMP file via mail, which would cause e.g. Evolution to crash but is probably not limited to Evolution. For the stable distribution (woody) this problem has been fixed in version 0.17.0-2woody1. For the unstable distribution (sid) this problem has been fixed in version 0.22.0-3. We recommend that you upgrade your libgdk-pixbuf2 package. |
Original Source
Url : http://www.debian.org/security/2004/dsa-464 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10574 | |||
Oval ID: | oval:org.mitre.oval:def:10574 | ||
Title: | gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. | ||
Description: | gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2004-0111 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:845 | |||
Oval ID: | oval:org.mitre.oval:def:845 | ||
Title: | Red Hat Enterprise 3 gdk-pixbuf Denial of Service | ||
Description: | gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2004-0111 | Version: | 2 |
Platform(s): | Red Hat Enterprise Linux 3 | Product(s): | gdk-pixbuf |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:846 | |||
Oval ID: | oval:org.mitre.oval:def:846 | ||
Title: | Red Hat gdk-pixbuf Denial of Service | ||
Description: | gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2004-0111 | Version: | 2 |
Platform(s): | Red Hat Linux 9 | Product(s): | gdk-pixbuf |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 464-1 (gdk-pixbuf) File : nvt/deb_464_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4184 | GdkPixbuf BMP Image Handling DoS
GdkPixbuf contains a flaw that may allow a denial of service. The issue is triggered when parsing BMP images containing a "bfOffBits" field having an extremely large value, and will result in loss of availability for the application linked against the library. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-464.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2004-103.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:33:10 |
|