CVE-2017-1000422

Source
https://cve.org/CVERecord?id=CVE-2017-1000422
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000422.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-1000422
Downstream
Related
Published
2018-01-02T20:29:00.190Z
Modified
2026-03-13T22:20:31.054464Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gifgetlzw function resulting in memory corruption and potential code execution

References

Affected packages

Git / gitlab.gnome.org/GNOME/gdk-pixbuf

Affected ranges

Type
GIT
Repo
https://gitlab.gnome.org/GNOME/gdk-pixbuf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.36.8"
        }
    ]
}

Affected versions

2.*
2.21.3
2.21.4
2.21.6
2.21.7
2.22.0
2.22.1
2.23.0
2.23.1
2.23.2
2.23.3
2.23.4
2.23.5
2.24.0
2.25.0
2.25.2
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.26.5
2.27.0
2.27.1
2.27.2
2.27.3
2.28.0
2.29.0
2.29.1
2.29.2
2.29.3
2.30.0
2.30.1
2.30.2
2.30.3
2.30.4
2.30.5
2.30.6
2.30.7
2.30.8
2.31.0
2.31.1
2.31.2
2.31.3
2.31.4
2.31.5
2.31.6
2.31.7
2.32.0
2.32.1
2.33.1
2.33.2
2.34.0
2.35.1
2.35.2
2.35.3
2.35.4
2.35.5
2.36.0
2.36.1
2.36.2
2.36.3
2.36.4
2.36.5
2.36.6
2.36.7
2.36.8

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "14.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "17.10"
            }
        ]
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000422.json"