PT-2020-6966 · Gnome+5 · Gdk-Pixbuf+5

Mdeslaurper

·

Published

2020-12-08

·

Updated

2025-04-29

·

CVE-2020-29385

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNOME gdk-pixbuf (aka GdkPixbuf) versions prior to 2.42.2
Description The issue is related to the execution of a loop with an inaccessible exit condition in the GdkPixbuf library, which can be exploited to cause a denial of service (infinite loop). This can occur in the write indexes function in lzw.c when c->self code equals 10, leading to an infinite assignment of values between self->code table[10].extends and self->code table[11].extends. This bug can be triggered by calling the function with a specially crafted GIF image that uses LZW compression.
Recommendations For versions prior to 2.42.2, update to version 2.42.2 or later to resolve the issue. As a temporary workaround, consider avoiding the use of GIF images with LZW compression until the issue is resolved.

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3463
BDU:2024-02767
CVE-2020-29385
OESA-2022-1762
OPENSUSE-SU-2021:0150-1
OPENSUSE-SU-2021_0150-1
OPENSUSE-SU-2024:10779-1
SUSE-SU-2021:0184-1
SUSE-SU-2021_0184-1
USN-4663-1

Affected Products

Alt Linux
Gdk-Pixbuf
Linuxmint
Red Os
Suse
Ubuntu