7.8
CVSSv3

CVE-2021-46829

Published: 24/07/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

GNOME GdkPixbuf (aka GDK-PixBuf) prior to 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdk-pixbuf

fedoraproject fedora 35

debian debian linux 11.0

Vendor Advisories

Synopsis Moderate: gdk-pixbuf2 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for gdk-pixbuf2 is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as hav ...
Several vulnerabilities were discovered in gdk-pixbuf, the GDK Pixbuf library CVE-2021-44648 Sahil Dhar reported a heap-based buffer overflow vulnerability when decoding the lzw compressed stream of image data, which may result in the execution of arbitrary code or denial of service if a malformed GIF image is processed CVE-2021- ...
GNOME GdkPixbuf (aka GDK-PixBuf) before 2428 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animationc composite_frame This overflow is controllable and could be abused for code execution, especially on 32-bit systems ...
heap buffer overflow when composing or clearing frames in GIF files ...