Back

HIGH

security flaw

Published Sep 17, 2004

Description

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

Affected products

Remediation

No remediation recorded yet.

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 17, 2004
Updated Aug 8, 2024
Reserved Aug 17, 2004
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 15, 2004
ENISA EUVD
Assigner mitre
Published Sep 17, 2004
Updated Aug 8, 2024
Exploited since n/a
EUVD-2004-0781