Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-2216

Опубликовано: 15 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-2216: gdk-pixbuf2 security update (MODERATE)

[2.42.6-3]

  • Backport fixes for CVE-2021-46829 and CVE-2021-44648
  • Resolves: rhbz#2115213
  • Resolves: rhbz#2044346

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gdk-pixbuf2

2.42.6-3.el9

gdk-pixbuf2-devel

2.42.6-3.el9

gdk-pixbuf2-modules

2.42.6-3.el9

Oracle Linux x86_64

gdk-pixbuf2

2.42.6-3.el9

gdk-pixbuf2-devel

2.42.6-3.el9

gdk-pixbuf2-modules

2.42.6-3.el9

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVSS3: 7.3
redhat
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVSS3: 8.8
nvd
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVSS3: 8.8
debian
больше 3 лет назад

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulner ...

CVSS3: 7.8
ubuntu
почти 3 года назад

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.