7.8
CVSSv3

CVE-2021-46829

Published: 24/07/2022 Updated: 27/10/2022
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8

Vulnerability Summary

GNOME GdkPixbuf (aka GDK-PixBuf) prior to 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdk-pixbuf

fedoraproject fedora 35

debian debian linux 11.0

Vendor Advisories

Several vulnerabilities were discovered in gdk-pixbuf, the GDK Pixbuf library CVE-2021-44648 Sahil Dhar reported a heap-based buffer overflow vulnerability when decoding the lzw compressed stream of image data, which may result in the execution of arbitrary code or denial of service if a malformed GIF image is processed CVE-2021- ...
GNOME GdkPixbuf (aka GDK-PixBuf) before 2428 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animationc composite_frame This overflow is controllable and could be abused for code execution, especially on 32-bit systems ...
heap buffer overflow when composing or clearing frames in GIF files ...

Github Repositories

CVE-2021-46829 GNOME GdkPixbuf (aka GDK-PixBuf) before 2428 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animationc composite_frame This overflow is controllable and could be abused for code execution, especially on 32-bit systems authentication complexity vector not available not available not avail