Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported.
NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.
Package Name: gtk+
Package Version: [cpe:/a:gtk:gtk%2B:3.1.4]
Advisory: CVE-2005-2975
Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2005-2975
CVSS severity score: 7.8/10.0
Confidence: high
Description:
io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.
Comment 1 by wfh@chromium.org
, Oct 12 2017Labels: OS-Chrome
Owner: mnissler@chromium.org
Status: Assigned (was: Unconfirmed)