Описание
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C.
This issue affects giflib: through 5.2.2.
A flaw was found in the gif2rgb utility of giflib. This vulnerability allows an attacker to cause a heap-based buffer overflow via crafted GIF files. The issue arises due to improper handling of certain GIF image data, leading to memory corruption.
Отчет
java-*-openjdk-headless packages do not contain libawt.so, hence are not affected.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of OpenJDK 11 | java-11-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 17 | java-17-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 1.8 | java-1.8.0-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable | Not affected | ||
| Red Hat Enterprise Linux 10 | giflib | Fix deferred | ||
| Red Hat Enterprise Linux 10 | java-21-openjdk | Not affected | ||
| Red Hat Enterprise Linux 6 | giflib | Fix deferred | ||
| Red Hat Enterprise Linux 7 | giflib | Fix deferred | ||
| Red Hat Enterprise Linux 7 | java-1.8.0-openjdk | Not affected | ||
| Red Hat Enterprise Linux 8 | giflib | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.
The giflib open-source component has a buffer overflow vulnerability
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. ...
EPSS
5.9 Medium
CVSS3