Описание
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
A flaw was found in giflib, in the command-line tool gif2rgb. Information disclosure is possible due to a buffer overflow in the DumpScreen2RGB() function.
Отчет
This issue did not affect the versions of giflib as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 9 as they did not include the gif2rgb tool.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | giflib | Out of support scope | ||
Red Hat Enterprise Linux 7 | giflib | Out of support scope | ||
Red Hat Enterprise Linux 8 | giflib | Not affected | ||
Red Hat Enterprise Linux 9 | giflib | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RG ...
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
EPSS
5.5 Medium
CVSS3