Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 12 min 120 bronnen 1 kritiek 13 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2015-4491

MEDIUM · 6.8 CVSS Gepubliceerd: CWE-189

Beschrijving NL

Integer-overloop in de make_filter_table-functie in pixops/pixops.c in gdk-pixbuf vóór 2.31.5, zoals gebruikt in Mozilla Firefox vóór 40.0 en Firefox ESR 38.x vóór 38.2 op Linux, Google Chrome op Linux en andere producten, stelt externe aanvallers in staat om willekeurige code uit te voeren of een denial of service (op heap gebaseerde bufferoverloop en applicatiecrash) te veroorzaken via vervaardigde bitmapdimensies die tijdens het schalen verkeerd worden gebruikt.

Origineel (Engels) tonen

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

Vendors

Gnome Google Mozilla Linux Oracle Canonical Fedoraproject Opensuse

Affected products

Gdk-pixbuf Chrome Firefox Linux Kernel Solaris Ubuntu Linux Fedora Opensuse

References