Описание
Security update for giflib
This update for giflib fixes the following issues:
Update to version 5.2.2
- Fixes for CVE-2023-48161 (bsc#1217390), CVE-2022-28506 (bsc#1198880)
- #138 Documentation for obsolete utilities still installed
- #139: Typo in 'LZW image data' page ('110_2 = 4_10')
- #140: Typo in 'LZW image data' page ('LWZ')
- #141: Typo in 'Bits and bytes' page ('filed')
- Note as already fixed SF issue #143: cannot compile under mingw
- #144: giflib-5.2.1 cannot be build on windows and other platforms using c89
- #145: Remove manual pages installation for binaries that are not installed too
- #146: [PATCH] Limit installed man pages to binaries, move giflib to section 7
- #147 [PATCH] Fixes to doc/whatsinagif/ content
- #148: heap Out of Bound Read in gif2rgb.c:298 DumpScreen2RGB
- Declared no-info on SF issue #150: There is a denial of service vulnerability in GIFLIB 5.2.1
- Declared Won't-fix on SF issue 149: Out of source builds no longer possible
- #151: A heap-buffer-overflow in gif2rgb.c:294:45
- #152: Fix some typos on the html documentation and man pages
- #153: Fix segmentation faults due to non correct checking for args
- #154: Recover the giffilter manual page
- #155: Add gifsponge docs
- #157: An OutofMemory-Exception or Memory Leak in gif2rgb
- #158: There is a null pointer problem in gif2rgb
- #159 A heap-buffer-overflow in GIFLIB5.2.1 DumpScreen2RGB() in gif2rgb.c:298:45
- #163: detected memory leaks in openbsd_reallocarray giflib/openbsd-reallocarray.c
- #164: detected memory leaks in GifMakeMapObject giflib/gifalloc.c
- #166: a read zero page leads segment fault in getarg.c and memory leaks in gif2rgb.c and gifmalloc.c
- #167: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function at Line 321 of gif2rgb.c
Список пакетов
Container bci/openjdk-devel:11
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:17
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:latest
libgif7-5.2.2-150000.4.13.1
Container containers/apache-pulsar:3.3
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk11
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk17
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk21
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk11
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk17
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk21
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk8
libgif7-5.2.2-150000.4.13.1
Container suse/manager/5.0/x86_64/server:latest
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
libgif7-5.2.2-150000.4.13.1
Image server-image
libgif7-5.2.2-150000.4.13.1
Image tomcat_15_6
libgif7-5.2.2-150000.4.13.1
SUSE Enterprise Storage 7.1
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP2-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP3-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP4-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Manager Proxy 4.3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Manager Server 4.3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
openSUSE Leap 15.5
giflib-devel-5.2.2-150000.4.13.1
giflib-devel-32bit-5.2.2-150000.4.13.1
giflib-progs-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
libgif7-32bit-5.2.2-150000.4.13.1
Ссылки
- Link for SUSE-SU-2024:0786-1
- E-Mail link for SUSE-SU-2024:0786-1
- SUSE Security Ratings
- SUSE Bug 1198880
- SUSE Bug 1200551
- SUSE Bug 1217390
- SUSE CVE CVE-2021-40633 page
- SUSE CVE CVE-2022-28506 page
- SUSE CVE CVE-2023-48161 page
Описание
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1
Ссылки
- CVE-2021-40633
- SUSE Bug 1200551
Описание
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1
Ссылки
- CVE-2022-28506
- SUSE Bug 1198880
Описание
Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c
Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1
Ссылки
- CVE-2023-48161
- SUSE Bug 1217390