Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-4491
HistoryAug 11, 2015 - 12:00 a.m.

CVE-2015-4491

2015-08-1100:00:00
ubuntu.com
ubuntu.com
16

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.013

Percentile

85.8%

Integer overflow in the make_filter_table function in pixops/pixops.c in
gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and
Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other
products, allows remote attackers to execute arbitrary code or cause a
denial of service (heap-based buffer overflow and application crash) via
crafted bitmap dimensions that are mishandled during scaling.

Bugs

Notes

Author Note
mdeslaur initial gdk-pixbuf fix was incomplete
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 40.0+build4-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchfirefox< 40.0+build4-0ubuntu0.14.04.1UNKNOWN
ubuntu15.04noarchfirefox< 40.0+build4-0ubuntu0.15.04.1UNKNOWN
ubuntu12.04noarchgdk-pixbuf< 2.26.1-1ubuntu1.2UNKNOWN
ubuntu14.04noarchgdk-pixbuf< 2.30.7-0ubuntu1.1UNKNOWN
ubuntu15.04noarchgdk-pixbuf< 2.31.3-1ubuntu0.1UNKNOWN
ubuntu12.04noarchthunderbird< 1:38.2.0+build1-0ubuntu0.12.04.2UNKNOWN
ubuntu14.04noarchthunderbird< 1:38.2.0+build1-0ubuntu0.14.04.1UNKNOWN
ubuntu15.04noarchthunderbird< 1:38.2.0+build1-0ubuntu0.15.04.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.013

Percentile

85.8%