Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:0786-1

Опубликовано: 06 мар. 2024
Источник: suse-cvrf

Описание

Security update for giflib

This update for giflib fixes the following issues:

Update to version 5.2.2

  • Fixes for CVE-2023-48161 (bsc#1217390), CVE-2022-28506 (bsc#1198880)
  • #138 Documentation for obsolete utilities still installed
  • #139: Typo in 'LZW image data' page ('110_2 = 4_10')
  • #140: Typo in 'LZW image data' page ('LWZ')
  • #141: Typo in 'Bits and bytes' page ('filed')
  • Note as already fixed SF issue #143: cannot compile under mingw
  • #144: giflib-5.2.1 cannot be build on windows and other platforms using c89
  • #145: Remove manual pages installation for binaries that are not installed too
  • #146: [PATCH] Limit installed man pages to binaries, move giflib to section 7
  • #147 [PATCH] Fixes to doc/whatsinagif/ content
  • #148: heap Out of Bound Read in gif2rgb.c:298 DumpScreen2RGB
  • Declared no-info on SF issue #150: There is a denial of service vulnerability in GIFLIB 5.2.1
  • Declared Won't-fix on SF issue 149: Out of source builds no longer possible
  • #151: A heap-buffer-overflow in gif2rgb.c:294:45
  • #152: Fix some typos on the html documentation and man pages
  • #153: Fix segmentation faults due to non correct checking for args
  • #154: Recover the giffilter manual page
  • #155: Add gifsponge docs
  • #157: An OutofMemory-Exception or Memory Leak in gif2rgb
  • #158: There is a null pointer problem in gif2rgb
  • #159 A heap-buffer-overflow in GIFLIB5.2.1 DumpScreen2RGB() in gif2rgb.c:298:45
  • #163: detected memory leaks in openbsd_reallocarray giflib/openbsd-reallocarray.c
  • #164: detected memory leaks in GifMakeMapObject giflib/gifalloc.c
  • #166: a read zero page leads segment fault in getarg.c and memory leaks in gif2rgb.c and gifmalloc.c
  • #167: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function at Line 321 of gif2rgb.c

Список пакетов

Container bci/openjdk-devel:11
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:17
libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:latest
libgif7-5.2.2-150000.4.13.1
Container containers/apache-pulsar:3.3
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk11
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk17
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:10.1-openjdk21
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk11
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk17
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk21
libgif7-5.2.2-150000.4.13.1
Container containers/apache-tomcat:9-openjdk8
libgif7-5.2.2-150000.4.13.1
Container suse/manager/5.0/x86_64/server:latest
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
libgif7-5.2.2-150000.4.13.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
libgif7-5.2.2-150000.4.13.1
Image server-image
libgif7-5.2.2-150000.4.13.1
Image tomcat_15_6
libgif7-5.2.2-150000.4.13.1
SUSE Enterprise Storage 7.1
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP2-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP3-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server 15 SP4-LTSS
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Manager Proxy 4.3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
SUSE Manager Server 4.3
giflib-devel-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
openSUSE Leap 15.5
giflib-devel-5.2.2-150000.4.13.1
giflib-devel-32bit-5.2.2-150000.4.13.1
giflib-progs-5.2.2-150000.4.13.1
libgif7-5.2.2-150000.4.13.1
libgif7-32bit-5.2.2-150000.4.13.1

Описание

A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.


Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1

Ссылки

Описание

There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.


Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1

Ссылки

Описание

Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c


Затронутые продукты
Container bci/openjdk-devel:11:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:17:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk-devel:latest:libgif7-5.2.2-150000.4.13.1
Container bci/openjdk:11:libgif7-5.2.2-150000.4.13.1

Ссылки