Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44648

Опубликовано: 12 янв. 2022
Источник: debian
EPSS Низкий

Описание

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gdk-pixbuffixed2.42.9+dfsg-1package
gdk-pixbufnot-affectedbusterpackage
gdk-pixbufnot-affectedstretchpackage

Примечания

  • https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/136

  • https://sahildhar.github.io/blogpost/GdkPixbuf-Heap-Buffer-Overflow-in-lzw_decoder_new/

  • Introduced by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/b88f1ce91a610a4e491a4ad6352183791e78afac (2.39.2)

  • https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/130

  • https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/76eda67dbc3f48c9dd6815a5aaf6014ea4a16771 (2.42.9)

  • https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/0cf97225c9c227d11fc4ddf9cba8e8480672ee1b (2.42.9)

  • Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/19ebba03117aefc9d0312f675f3a210ffdcc4907 (2.42.9)

  • Tests: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/449441210921c8ed417b0c4d5edbccd2d57e23f8 (2.42.9)

EPSS

Процентиль: 39%
0.00168
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVSS3: 7.3
redhat
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVSS3: 8.8
nvd
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

suse-cvrf
почти 3 года назад

Security update for gdk-pixbuf

suse-cvrf
почти 3 года назад

Security update for gdk-pixbuf

EPSS

Процентиль: 39%
0.00168
Низкий