Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-23922

Опубликовано: 21 апр. 2021
Источник: debian

Описание

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
giflibfixed5.2.2-1package

Примечания

  • https://sourceforge.net/p/giflib/bugs/151/

  • Specific to gif2rgb. Crash in CLI tool, no security impact

  • Reproducer does not trigger using giflib 5.2.1-2.5 with asan or valgrind.

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

CVSS3: 5.5
redhat
почти 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

CVSS3: 7.1
nvd
почти 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

CVSS3: 7.1
github
больше 3 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.