CVE-2004-0782
gtk+2.0 - multiple holes
EPSS 31.1%
Description
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).
How to fix CVE-2004-0782
To remediate CVE-2004-0782, upgrade the affected package to a fixed version below.
- Debian/gdk-pixbuf—upgrade to 0.22.0-7 or later
- —upgrade to 2.4.9-2 or later
- —upgrade to 2.0.2-5woody2 or later
Is CVE-2004-0782 being exploited?
Moderate — EPSS is 31.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 0.22.0-7
- from 0, < 2.4.9-2
- from 0, < 2.0.2-5woody2