Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 831077 (CVE-2021-44648) - x11-libs/gdk-pixbuf: heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files (CVE-2021-44648)
Summary: x11-libs/gdk-pixbuf: heap-buffer overflow vulnerability when decoding the lzw...
Status: CONFIRMED
Alias: CVE-2021-44648
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://gitlab.gnome.org/GNOME/gdk-pi...
Whiteboard: B3 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-12 16:43 UTC by filip ambroz
Modified: 2022-01-12 16:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description filip ambroz 2022-01-12 16:43:40 UTC
The GdkPixbuf library is vulnerable to heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

URLs:
https://nvd.nist.gov/vuln/detail/CVE-2021-44648
https://sahildhar.github.io/blogpost/GdkPixbuf-Heap-Buffer-Overflow-in-lzw_decoder_new/

Reproducible: Always