Heap-based buffer overflow in Opensuse - CVE-2015-7552
Published: April 18, 2016 / Updated: August 9, 2020
Opensuse
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x. A remote attacker can use a crafted BMP file. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2015-7552
Sources
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00124.html
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00006.html
- http://www.debian.org/security/2016/dsa-3589
- http://www.ubuntu.com/usn/USN-3085-1
- https://bugzilla.suse.com/show_bug.cgi?id=958963
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJF5ARFOX4BFUK6YCBKGAKBQYECO3AI2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSAZ6UCKKXC5VOWXGWQHOX2ZBLLATIOT/