Description
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5228-1 | gdk-pixbuf security update |
EUVD |
EUVD-2021-33484 | GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems. |
Ubuntu USN |
USN-5554-1 | GDK-PixBuf vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T05:17:42.630Z
Reserved: 2022-07-24T00:00:00.000Z
Link: CVE-2021-46829
No data.
Status : Modified
Published: 2022-07-24T19:15:10.097
Modified: 2024-11-21T06:34:46.747
Link: CVE-2021-46829
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN