Описание
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Low, as it requires user interaction and local access to exploit. The flaw allows limited information disclosure by including uninitialized memory in image buffers processed by GdkPixbuf. This occurs due to improper output length handling when decoding malformed GIFs using LZW compression. While exploitable with crafted inputs, the impact is minor and does not affect system integrity or availability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | gdk-pixbuf2 | Fix deferred | ||
Red Hat Enterprise Linux 10 | glycin-loaders | Fix deferred | ||
Red Hat Enterprise Linux 10 | loupe | Fix deferred | ||
Red Hat Enterprise Linux 10 | snapshot | Fix deferred | ||
Red Hat Enterprise Linux 6 | gdk-pixbuf2 | Out of support scope | ||
Red Hat Enterprise Linux 7 | gdk-pixbuf2 | Fix deferred | ||
Red Hat Enterprise Linux 8 | gdk-pixbuf2 | Fix deferred | ||
Red Hat Enterprise Linux 9 | gdk-pixbuf2 | Fix deferred | ||
Red Hat Enterprise Linux 9 | librsvg2 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
A flaw was found in the GIF parser of GdkPixbuf\u2019s LZW decoder. Wh ...
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
EPSS
3.3 Low
CVSS3