rpm package
opensuse/gtk2&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/gtk2&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-6655 | Hig | 7.0 | < 2.24.33-10.1 | 2.24.33-10.1 | Jul 16, 2024 | A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory. | |
| CVE-2013-7447 | Med | 6.5 | < 2.24.31-1.2 | 2.24.31-1.2 | Feb 17, 2016 | Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, | |
| CVE-2007-0010 | — | < 2.24.33-1.9 | 2.24.33-1.9 | Jan 24, 2007 | The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file. | ||
| CVE-2005-2975 | — | < 2.24.33-1.9 | 2.24.33-1.9 | Nov 18, 2005 | io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors. |
- affected < 2.24.33-10.1fixed 2.24.33-10.1
A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.
- affected < 2.24.31-1.2fixed 2.24.31-1.2
Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file,
- CVE-2007-0010Jan 24, 2007affected < 2.24.33-1.9fixed 2.24.33-1.9
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.
- CVE-2005-2975Nov 18, 2005affected < 2.24.33-1.9fixed 2.24.33-1.9
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.