VDB

DEBIAN-CVE-2015-4491

DEBIAN-CVE-2015-4491 PUBLISHED CVSS 9.300000190734863 CRITICAL

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:14gtk+2.00, 0, 0
Debian:11gtk+2.00, 0, 0
Debian:13gdk-pixbuf0, 0, 0
Debian:12gtk+2.00, 0, 0
Debian:14gdk-pixbuf0, 0, 0
Debian:13gtk+2.00, 0, 0
Debian:11gdk-pixbuf0, 0, 0
Debian:12gdk-pixbuf0, 0, 0

Timeline

  • Aug 16, 2015 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›