Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
DLA-4225-1 | gdk-pixbuf security update |
![]() |
DSA-5946-1 | gdk-pixbuf security update |
![]() |
EUVD-2025-18505 | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image. |
![]() |
USN-7662-1 | GDK-PixBuf vulnerabilities |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Thu, 21 Aug 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gnome
Gnome gdkpixbuf |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:gnome:gdkpixbuf:2.0.0:-:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Gnome
Gnome gdkpixbuf |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 18 Jun 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 17 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image. | |
Title | Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder | |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
Weaknesses | CWE-200 | |
CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-03T02:12:32.297Z
Reserved: 2025-06-17T11:58:17.009Z
Link: CVE-2025-6199

Updated: 2025-06-17T14:43:16.070Z

Status : Analyzed
Published: 2025-06-17T15:15:54.307
Modified: 2025-08-21T01:16:43.190
Link: CVE-2025-6199


No data.