Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39742

Опубликовано: 25 авг. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

A flaw was found in giflib. This vulnerability, located in the getarg.c component, can lead to a segmentation fault when processing specially crafted input. This issue can result in a Denial of Service (DoS), making the application unavailable.

Отчет

This vulnerability is a segmentation fault triggered when the library's argument-parsing utility encounters unexpected input or malformed command-line arguments. This leads to a local Denial of Service (DoS), causing the utility to crash during execution. Because the impact is limited to the local process and does not facilitate unauthorized access or persistent service disruption, the overall security risk is considered low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6giflibOut of support scope
Red Hat Enterprise Linux 7giflibOut of support scope
Red Hat Enterprise Linux 8giflibFix deferred
Red Hat Enterprise Linux 9giflibFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2235821giflib: giflib: Denial of Service via getarg.c

EPSS

Процентиль: 25%
0.00328
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
nvd
почти 3 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
msrc
больше 1 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
debian
почти 3 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the c ...

CVSS3: 5.5
github
почти 3 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

EPSS

Процентиль: 25%
0.00328
Низкий

5.5 Medium

CVSS3