Back

MEDIUM

Mozilla: Heap overflow in gdk-pixbuf when scaling bitmap images (MFSA 2015-88)

Published Aug 16, 2015

Description

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of gdk-pixbuf as shipped with Red Hat Enterprise Linux 5.

Metrics

Weaknesses (2)

References (36)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Aug 16, 2015
Updated Aug 6, 2024
Reserved Jun 10, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 11, 2015