CVE ID CVE-2017-2870 (nvd) (mitre) (debian) (archlinux) (red hat) (suse) (ubuntu)
Affected Package(s) gdk-pixbuf
Deficiency Type SECURITY
Date Created 2017-09-05 17:13:35
Date Last Modified 2017-09-05 17:52:41

Cucumber 1.0 i686fixed in gdk-pixbuf-2.36.9-i686-1
Cucumber 1.0 x86_64fixed in gdk-pixbuf-2.36.9-x86_64-1 and gdk-pixbuf-lib_i686-2.36.9-lib_i686-1

Cucumber 1.1 i686 fixed in gdk-pixbuf-2.36.9-i686-1
Cucumber 1.1 x86_64 fixed in gdk-pixbuf-2.36.9-x86_64-1 and gdk-pixbuf-lib_i686-2.36.9-lib_i686-1


An exploitable integer overflow vulnerability exists in the tiff_image_parse
functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted
tiff file can cause a heap-overflow resulting in remote code execution. An
attacker can send a file or a URL to trigger this vulnerability

Despite the NVD entry, the Gnome developers claim that this vulnerable is
agnostic to the compiler used. NVD probably mentioned Clang because that was
the compiler used in the original report.

This is Gnome Bug 780269 (,
which was fixed in gdk-pixbuf 2.36.7

