A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
| Vendor | Product | Versions |
|---|---|---|
| gdk | — | — |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | gdk-pixbuf | cert_advisory | 90% |
Updated severity to HIGH and marked the vulnerability as actively exploited with an exploit available.
Initial creation