Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165701.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165703.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165730.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165732.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00030.html
http://lists.opensuse.org/opensuse-updates/2015-08/msg00031.html
http://lists.opensuse.org/opensuse-updates/2015-09/msg00002.html
http://rhn.redhat.com/errata/RHSA-2015-1586.html
http://rhn.redhat.com/errata/RHSA-2015-1682.html
http://rhn.redhat.com/errata/RHSA-2015-1694.html
http://www.debian.org/security/2015/dsa-3337
http://www.mozilla.org/security/announce/2015/mfsa2015-88.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.securitytracker.com/id/1033247
http://www.securitytracker.com/id/1033372
http://www.ubuntu.com/usn/USN-2702-1
http://www.ubuntu.com/usn/USN-2702-2
http://www.ubuntu.com/usn/USN-2702-3
http://www.ubuntu.com/usn/USN-2712-1
http://www.ubuntu.com/usn/USN-2722-1
https://bugzilla.gnome.org/show_bug.cgi?id=752297
https://bugzilla.mozilla.org/show_bug.cgi?id=1184009
https://bugzilla.redhat.com/show_bug.cgi?id=1252290
https://git.gnome.org/browse/gdk-pixbuf/commit/?id=ffec86ed5010c5a2be14f47b33bcf4ed3169a199
AND
OR
OR
cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124941 | EulerOS Virtualization 3.0.1.0 : gdk-pixbuf2 (EulerOS-SA-2019-1438) | Nessus | Huawei Local Security Checks | medium |
111627 | openSUSE Security Update : gdk-pixbuf (openSUSE-2018-846) | Nessus | SuSE Local Security Checks | medium |
111506 | SUSE SLED12 / SLES12 Security Update : gdk-pixbuf (SUSE-SU-2018:2145-1) | Nessus | SuSE Local Security Checks | medium |
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
88995 | Debian DLA-434-1 : gtk+2.0 security update | Nessus | Debian Local Security Checks | medium |
87646 | SUSE SLED12 / SLES12 Security Update : gdk-pixbuf (SUSE-SU-2015:2195-2) | Nessus | SuSE Local Security Checks | medium |
87546 | GLSA-201512-05 : gdk-pixbuf: Multiple Vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
87215 | SUSE SLED12 / SLES12 Security Update : gdk-pixbuf (SUSE-SU-2015:2195-1) | Nessus | SuSE Local Security Checks | medium |
87063 | SUSE SLES10 Security Update : Mozilla Firefox (SUSE-SU-2015:2081-1) | Nessus | SuSE Local Security Checks | critical |
86536 | SUSE SLED11 / SLES11 Security Update : gtk2 (SUSE-SU-2015:1787-1) | Nessus | SuSE Local Security Checks | medium |
86499 | CentOS 6 / 7 : gdk-pixbuf2 (CESA-2015:1694) | Nessus | CentOS Local Security Checks | medium |
86497 | CentOS 5 / 6 / 7 : thunderbird (CESA-2015:1682) | Nessus | CentOS Local Security Checks | critical |
85906 | SUSE SLED11 / SLES11 Security Update : MozillaFirefox, mozilla-nss (SUSE-SU-2015:1528-1) | Nessus | SuSE Local Security Checks | critical |
8856 | Mozilla Firefox < 40.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
85839 | openSUSE Security Update : gdk-pixbuf (openSUSE-2015-570) | Nessus | SuSE Local Security Checks | medium |
85819 | Fedora 22 : mingw-gdk-pixbuf-2.31.6-1.fc22 (2015-14011) | Nessus | Fedora Local Security Checks | medium |
85818 | Fedora 21 : mingw-gdk-pixbuf-2.31.6-1.fc21 (2015-14010) | Nessus | Fedora Local Security Checks | medium |
85817 | Fedora 21 : gdk-pixbuf2-2.31.6-1.fc21 (2015-13926) | Nessus | Fedora Local Security Checks | medium |
85816 | Fedora 22 : gdk-pixbuf2-2.31.6-1.fc22 (2015-13925) | Nessus | Fedora Local Security Checks | medium |
85763 | SUSE SLED12 / SLES12 Security Update : MozillaFirefox, mozilla-nss (SUSE-SU-2015:1476-1) | Nessus | SuSE Local Security Checks | critical |
85725 | Slackware 13.37 / 14.0 / 14.1 / current : gdk-pixbuf2 (SSA:2015-244-01) | Nessus | Slackware Local Security Checks | medium |
85721 | SUSE SLES11 Security Update : MozillaFirefox, mozilla-nss (SUSE-SU-2015:1449-1) (Logjam) | Nessus | SuSE Local Security Checks | critical |
85717 | RHEL 6 / 7 : gdk-pixbuf2 (RHSA-2015:1694) | Nessus | Red Hat Local Security Checks | medium |
85710 | Oracle Linux 6 / 7 : gdk-pixbuf2 (ELSA-2015-1694) | Nessus | Oracle Linux Local Security Checks | medium |
85703 | openSUSE Security Update : MozillaThunderbird (openSUSE-2015-559) | Nessus | SuSE Local Security Checks | critical |
85702 | openSUSE Security Update : MozillaThunderbird (openSUSE-2015-558) | Nessus | SuSE Local Security Checks | critical |
85660 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : gdk-pixbuf vulnerability (USN-2722-1) | Nessus | Ubuntu Local Security Checks | medium |
85648 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : thunderbird vulnerabilities (USN-2712-1) | Nessus | Ubuntu Local Security Checks | critical |
85646 | Scientific Linux Security Update : thunderbird on SL5.x, SL6.x, SL7.x i386/x86_64 (20150825) | Nessus | Scientific Linux Local Security Checks | critical |
85645 | RHEL 5 / 6 / 7 : thunderbird (RHSA-2015:1682) | Nessus | Red Hat Local Security Checks | critical |
85642 | Oracle Linux 6 / 7 : thunderbird (ELSA-2015-1682) | Nessus | Oracle Linux Local Security Checks | critical |
85578 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox regression (USN-2702-3) | Nessus | Ubuntu Local Security Checks | critical |
85562 | FreeBSD : gdk-pixbuf2 -- heap overflow and DoS (f5b8b670-465c-11e5-a49d-bcaec565249c) | Nessus | FreeBSD Local Security Checks | medium |
85517 | Debian DSA-3337-1 : gdk-pixbuf - security update | Nessus | Debian Local Security Checks | medium |
85437 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-548) | Nessus | SuSE Local Security Checks | critical |
85436 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-547) | Nessus | SuSE Local Security Checks | critical |
85345 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : ubufox update (USN-2702-2) | Nessus | Ubuntu Local Security Checks | critical |
85344 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox vulnerabilities (USN-2702-1) | Nessus | Ubuntu Local Security Checks | critical |
85343 | Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20150811) | Nessus | Scientific Linux Local Security Checks | critical |
85342 | RHEL 5 / 6 / 7 : firefox (RHSA-2015:1586) | Nessus | Red Hat Local Security Checks | critical |
85339 | Oracle Linux 5 / 6 / 7 : firefox (ELSA-2015-1586) | Nessus | Oracle Linux Local Security Checks | critical |
85338 | FreeBSD : mozilla -- multiple vulnerabilities (c66a5632-708a-4727-8236-d65b2d5b2739) | Nessus | FreeBSD Local Security Checks | critical |
85336 | CentOS 5 / 6 / 7 : firefox (CESA-2015:1586) | Nessus | CentOS Local Security Checks | critical |