CVE-2005-0891 describes a double free vulnerability in GTK 2 (gtk2) versions prior to 2.2.4, specifically affecting GNOME GTK. This flaw allows remote attackers to trigger a denial of service (crash) by providing a specially crafted BMP image. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over a network without user interaction, leading to high availability impact. While no known public exploits or active exploitation have been identified, and community discussion is minimal, the potential for a denial of service remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.2.4CPE matchmatch criteria | cpe:2.3:a:gnome:gtk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.