CVE-2015-4491: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 8.4% chance of exploitation in the next 30 days.
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Fedoraproject Fedora: version 21 only; version 22 only
- Gnome Gdk-Pixbuf: up to and including 2.31.4
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 10 only; version 11.3 only
Published 2015-08-16. Last modified 2026-06-17.