Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20240

Опубликовано: 19 янв. 2021
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

A flaw was found in gdk-pixbuf. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This issue did not affect the versions of gdk-pixbuf2 as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gdk-pixbuf2Not affected
Red Hat Enterprise Linux 7gdk-pixbuf2Not affected
Red Hat Enterprise Linux 8gdk-pixbuf2Not affected
Red Hat Enterprise Linux 9gdk-pixbuf2Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1926787gdk-pixbuf: integer wraparound in the GIF loader of gdk-pixbuf via crafted input leads to segmentation fault

EPSS

Процентиль: 73%
0.00794
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.8
nvd
около 4 лет назад

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.8
debian
около 4 лет назад

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer w ...

CVSS3: 8.8
github
около 3 лет назад

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость библиотеки загрузки изображений GdkPixbuf, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 73%
0.00794
Низкий

8.1 High

CVSS3