Vulnerability Description
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gdkpixbuf | All versions |
| Gnome | Gtk | < 2.8.7 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/17522Broken LinkVendor Advisory
- http://secunia.com/advisories/17538Broken LinkVendor Advisory
- http://secunia.com/advisories/17562Broken LinkVendor Advisory
- http://secunia.com/advisories/17588Broken LinkVendor Advisory
- http://secunia.com/advisories/17591Broken LinkVendor Advisory
- http://secunia.com/advisories/17592Broken Link
- http://secunia.com/advisories/17594Broken LinkVendor Advisory
- http://secunia.com/advisories/17615Broken LinkVendor Advisory
- http://secunia.com/advisories/17657Broken LinkVendor Advisory
- http://secunia.com/advisories/17710Broken LinkVendor Advisory
- http://secunia.com/advisories/17770Broken LinkVendor Advisory
- http://secunia.com/advisories/17791Broken LinkVendor Advisory
- http://securitytracker.com/id?1015216Broken LinkThird Party AdvisoryVDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2005-229.pdfThird Party Advisory
- http://www.debian.org/security/2005/dsa-911Third Party Advisory
FAQ
What is CVE-2005-2975?
CVE-2005-2975 is a vulnerability with a CVSS score of 7.8 (HIGH). io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
How severe is CVE-2005-2975?
CVE-2005-2975 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2975?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Gdkpixbuf, Gnome Gtk.