CVE-2015-8875

NameCVE-2015-8875
DescriptionMultiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-450-1, DSA-3589-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gdk-pixbuf (PTS)wheezy2.26.1-1+deb7u3vulnerable
wheezy (security)2.26.1-1+deb7u6fixed
jessie2.31.1-2+deb8u5fixed
jessie (security)2.31.1-2+deb8u6fixed
stretch (security), stretch2.36.5-2+deb9u1fixed
buster, sid2.36.11-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gdk-pixbufsource(unstable)2.34.0-1medium
gdk-pixbufsourcejessie2.31.1-2+deb8u5mediumDSA-3589-1
gdk-pixbufsourcewheezy2.26.1-1+deb7u4mediumDLA-450-1

Notes

Fixed by: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=dbfe8f70471864818bf458a39c8a99640895bd22 (2.33.1)
http://www.openwall.com/lists/oss-security/2016/05/12/3

Search for package or bug name: Reporting problems