Vulnerability Name:

CVE-2007-0010 (CCN-31787)

Assigned:2006-12-19
Published:2007-01-10
Updated:2022-02-07
Summary:The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-0010

Source: CCN
Type: ftp.gtk.org Web site
[gnome] Diff of /gtk+/gdk-pixbuf/gdk-pixbuf-loader.c

Source: OSVDB
Type: Broken Link
31621

Source: CCN
Type: RHSA-2007-0019
Moderate: gtk2 security update

Source: CCN
Type: SA23884
GTK+ "GdkPixbufLoader()" Denial of Service

Source: SECUNIA
Type: Broken Link
23884

Source: SECUNIA
Type: Broken Link
23933

Source: SECUNIA
Type: Broken Link
23935

Source: CCN
Type: SA23984
SUSE Update for Multiple Packages

Source: SECUNIA
Type: Broken Link
23984

Source: SECUNIA
Type: Broken Link
24006

Source: SECUNIA
Type: Broken Link
24010

Source: SECUNIA
Type: Broken Link
24095

Source: CCN
Type: SECTRACK ID: 1017552
GTK2 Input Validation Error in GdkPixbufLoader() Lets Remote Users Deny Service

Source: SECTRACK
Type: Broken Link, Third Party Advisory, VDB Entry
1017552

Source: CCN
Type: ASA-2007-053
gtk2 security update (RHSA-2007-0019)

Source: DEBIAN
Type: DSA-1256
gtk+2.0 -- programming error

Source: MANDRIVA
Type: Broken Link
MDKSA-2007:039

Source: SUSE
Type: Broken Link
SUSE-SR:2007:002

Source: CCN
Type: OSVDB ID: 31621
GTK+ GdkPixbufLoader Image Handling DoS

Source: REDHAT
Type: Broken Link, Vendor Advisory
RHSA-2007:0019

Source: BID
Type: Broken Link, Third Party Advisory, VDB Entry
22209

Source: CCN
Type: BID-22209
GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability

Source: CCN
Type: USN-415-1
GTK vulnerability

Source: UBUNTU
Type: Third Party Advisory
USN-415-1

Source: VUPEN
Type: Broken Link
ADV-2007-0331

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932

Source: XF
Type: UNKNOWN
gtk-gdkpixbufloader-dos(31787)

Source: CONFIRM
Type: Broken Link
https://issues.rpath.com/browse/RPL-984

Source: OVAL
Type: Tool Signature
oval:org.mitre.oval:def:10325

Source: DEBIAN
Type: Third Party Advisory
DSA-1256

Source: SUSE
Type: SUSE-SR:2007:002
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:gtk:*:*:*:*:*:*:*:* (Version < 2.4.13)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:42320
    P
    Security update for systemd-presets-common-SUSE (Moderate) (in QA)
    2022-07-13
    oval:org.opensuse.security:def:20070010
    V
    CVE-2007-0010
    2022-06-30
    oval:org.opensuse.security:def:112377
    P
    gtk2-branding-upstream-2.24.33-1.9 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:33068
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:26181
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:26171
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:32220
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:31696
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:26142
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:31690
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:105888
    P
    gtk2-branding-upstream-2.24.33-1.9 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:42122
    P
    Security update for the Linux Kernel (Important)
    2021-09-21
    oval:org.opensuse.security:def:31269
    P
    Security update for ghostscript (Critical)
    2021-09-21
    oval:org.opensuse.security:def:26119
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:31248
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:32156
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:26093
    P
    Security update for dbus-1 (Important)
    2021-07-21
    oval:org.opensuse.security:def:32134
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:31640
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:31637
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:36144
    P
    gtk2-2.18.9-0.23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36418
    P
    gtk2-devel-2.18.9-0.23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42551
    P
    gtk2-2.18.9-0.23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31184
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:31183
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:31622
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:32095
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:26043
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:26042
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:31611
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:26040
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:31610
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:26035
    P
    Security update for apache-commons-io (Moderate)
    2021-04-26
    oval:org.opensuse.security:def:32064
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:33107
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:31747
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:32276
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31745
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:26195
    P
    Security update for php74 (Important)
    2021-02-19
    oval:org.opensuse.security:def:31340
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:32200
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:31195
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:25984
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:32838
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:25979
    P
    Security update for xen (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:32003
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35913
    P
    gtk2-2.18.9-0.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35562
    P
    gtk2-2.18.9-0.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35715
    P
    gtk2-2.18.9-0.21.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41969
    P
    gtk2-2.18.9-0.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25967
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:26252
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25896
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25267
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31401
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26270
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25845
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32680
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25693
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31484
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:25342
    P
    Security update for raptor (Important)
    2020-12-01
    oval:org.opensuse.security:def:31550
    P
    Security update for shim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26646
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26680
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25705
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31920
    P
    Security update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:31849
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26469
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:31031
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25551
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:31990
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26699
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31380
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25897
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:25690
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31937
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27142
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25113
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31116
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25889
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:32325
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:32488
    P
    apache2-mod_perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31392
    P
    Security update for pam-modules (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25945
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:25125
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32386
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25464
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31598
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26544
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25998
    P
    Security update for libreoffice (Important)
    2020-12-01
    oval:org.opensuse.security:def:32877
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25317
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:26411
    P
    Security update for go (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26562
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25539
    P
    Security update for dbus-1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26877
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25455
    P
    Security update for libjpeg-turbo (Important)
    2020-12-01
    oval:org.opensuse.security:def:32046
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26743
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25748
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31806
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25843
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27416
    P
    gtk2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25266
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25831
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:32641
    P
    cifs-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26309
    P
    Security update for haproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:32430
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25278
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:31493
    P
    Security update for python
    2020-12-01
    oval:org.opensuse.security:def:26323
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25694
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31828
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31030
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25470
    P
    Security update for permissions (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31834
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26685
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26715
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25769
    P
    Security update for gd (Low)
    2020-12-01
    oval:org.opensuse.security:def:31977
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31898
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:27107
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31042
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:25608
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31850
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31381
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25978
    P
    Security update for tcpdump, libpcap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25743
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31959
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25114
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:32364
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:32527
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25463
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:31466
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26393
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25189
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31397
    P
    Security update for perl (Low)
    2020-12-01
    oval:org.opensuse.security:def:26372
    P
    Recommended update for geotiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26527
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25475
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:26597
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26239
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25968
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25398
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31793
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26425
    P
    Security update for pdns (Low)
    2020-12-01
    oval:org.opensuse.security:def:25667
    P
    Security update for u-boot (Important)
    2020-12-01
    oval:org.opensuse.security:def:31784
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26912
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25692
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27381
    P
    cpp48 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25805
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25792
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:10325
    V
    The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.
    2013-04-29
    oval:com.redhat.rhsa:def:20070019
    P
    RHSA-2007:0019: gtk2 security update (Moderate)
    2008-03-20
    oval:org.debian:def:1256
    V
    programming error
    2007-01-31
    BACK
    gnome gtk *