CVE-2012-2370: Gnome Gdk-Pixbuf
Medium severity, CVSS 5.0. EPSS: 4.1% chance of exploitation in the next 30 days.
Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow.
Affected products
- Gnome Gdk-Pixbuf: up to and including 2.26.0; version 2.23.3 only; version 2.23.4 only; version 2.23.5 only; version 2.24.0 only; version 2.24.1 only; …
Published 2012-08-13. Last modified 2026-06-16.