GNOME libgxps 0.2.5

CPE Details

GNOME libgxps 0.2.5
0.2.5
2019-06-10
15h03 +00:00
2019-06-10
15h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnome:libgxps:0.2.5:*:*:*:*:*:*:*

Informations

Vendor

gnome

Product

libgxps

Version

0.2.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10767 2018-05-06 21h00 +00:00 There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
6.5
Medium
CVE-2018-10733 2018-05-04 14h00 +00:00 There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
6.5
Medium
CVE-2017-11590 2017-07-23 23h00 +00:00 There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
7.5
High