Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39742

Опубликовано: 25 авг. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

A flaw was found in giflib. This vulnerability, located in the getarg.c component, can lead to a segmentation fault when processing specially crafted input. This issue can result in a Denial of Service (DoS), making the application unavailable.

Отчет

This vulnerability is a segmentation fault triggered when the library's argument-parsing utility encounters unexpected input or malformed command-line arguments. This leads to a local Denial of Service (DoS), causing the utility to crash during execution. Because the impact is limited to the local process and does not facilitate unauthorized access or persistent service disruption, the overall security risk is considered low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6giflibOut of support scope
Red Hat Enterprise Linux 7giflibOut of support scope
Red Hat Enterprise Linux 8giflibFix deferred
Red Hat Enterprise Linux 9giflibFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2235821giflib: giflib: Denial of Service via getarg.c

EPSS

Процентиль: 27%
0.00346
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
nvd
около 3 лет назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
msrc
больше 1 года назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

CVSS3: 5.5
debian
около 3 лет назад

giflib v5.2.1 was discovered to contain a segmentation fault via the c ...

CVSS3: 5.5
github
около 3 лет назад

giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.

EPSS

Процентиль: 27%
0.00346
Низкий

5.5 Medium

CVSS3