GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
2022-07-24T19:15:10.097
2024-11-21T06:34:46.747
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnome | gdk-pixbuf | < 2.42.8 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |