{"id":"CVE-2025-7345","title":"A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c)","summary":"A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur duri…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-120"],"published":"2025-07-08","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-7345","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:12841","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:12862","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:13315","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14574","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14575","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14576","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14585","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14618","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14646","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14647","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14683","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-7345","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2377063","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/249","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01157,"epssPercentile":0.65674,"ingestedAt":"2026-06-29T13:24:34.386Z","slug":"CVE-2025-7345","body":"## Overview\n\nA flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}