PublicDateAtUSN: 2015-10-02 Candidate: CVE-2015-7673 PublicDate: 2015-10-26 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7673 http://www.openwall.com/lists/oss-security/2015/10/01/3 https://ubuntu.com/security/notices/USN-2767-1 Description: io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file. Ubuntu-Description: Notes: mdeslaur> this is actually fixed in 2.32.0, not 2.32.1 Bugs: Priority: medium Discovered-by: Assigned-to: sbeattie CVSS: Patches_gdk-pixbuf: upstream: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=19f9685dbff7d1f929c61cf99188df917a18811d upstream: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=edf6fb8d856574bc3bb3a703037f56533229267c upstream: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=6ddca835100107e6b5841ce9d56074f6d98c387e upstream_gdk-pixbuf: released (2.32.0-1,2.32.1) precise_gdk-pixbuf: released (2.26.1-1ubuntu1.3) trusty_gdk-pixbuf: released (2.30.7-0ubuntu1.2) trusty/esm_gdk-pixbuf: DNE (trusty was released [2.30.7-0ubuntu1.2]) vivid_gdk-pixbuf: released (2.31.3-1ubuntu0.2) devel_gdk-pixbuf: not-affected (2.32.0-1) vivid/stable-phone-overlay_gdk-pixbuf: released (2.31.3-1ubuntu0.2) vivid/ubuntu-core_gdk-pixbuf: DNE