Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46829

Опубликовано: 24 июл. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

A heap-based buffer overflow vulnerability was found in GNOME GdkPixbuf (aka GDK-PixBuf) when compositing or clearing frames in GIF files. The vulnerability exists due to a boundary error when processing GIF images. This flaw allows an attacker to create a specially crafted GIF image, trick the victim into opening it, triggering an out-of-bounds write, which allows executing arbitrary code on the target system or causing a potential crash.

Отчет

Red Hat Enterprise Linux - 6, 7, and 8 are not affected because there is no presence of vulnerable function/code in our code-base.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gdk-pixbuf2Not affected
Red Hat Enterprise Linux 7gdk-pixbuf2Not affected
Red Hat Enterprise Linux 8gdk-pixbuf2Not affected
Red Hat Enterprise Linux 9gdk-pixbuf2FixedRHSA-2023:221609.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2114940gdk-pixbuf: heap-based buffer overflow when compositing or clearing frames in GIF files

EPSS

Процентиль: 63%
0.00465
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

CVSS3: 7.8
nvd
почти 3 года назад

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

CVSS3: 7.8
debian
почти 3 года назад

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buf ...

suse-cvrf
почти 3 года назад

Security update for gdk-pixbuf

suse-cvrf
почти 3 года назад

Security update for gdk-pixbuf

EPSS

Процентиль: 63%
0.00465
Низкий

7.8 High

CVSS3