PT-2021-7559 · Unknown+8 · Gdk-Pixbuf+8

Pedro Ribeiro

·

Published

2021-06-02

·

Updated

2024-06-15

·

CVE-2021-46829

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GdkPixbuf versions prior to 2.42.8
Description The issue is related to a heap-based buffer overflow in the composite frame() function of the GdkPixbuf library when handling GIF files. This overflow can be exploited to execute arbitrary code, particularly on 32-bit systems.
Recommendations For versions prior to 2.42.8, update to version 2.42.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the composite frame() function when handling GIF files until a patch is available.

Exploit

Fix

Heap Based Buffer Overflow

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2216
ALSA-2023_2216
ALT-PU-2022-1509
BDU:2023-00075
CVE-2021-46829
DSA-5228-1
ELSA-2023-2216
MGASA-2022-0269
OESA-2022-1873
OESA-2022-1874
OPENSUSE-SU-2022_2995-1
OPENSUSE-SU-2022_2996-1
OPENSUSE-SU-2024:12222-1
RHSA-2023:2216
RHSA-2023_2216
SUSE-SU-2022:2995-1
SUSE-SU-2022:2996-1
SUSE-SU-2022_2995-1
SUSE-SU-2022_2996-1
USN-5554-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Gdk-Pixbuf
Linuxmint
Red Hat
Red Os
Suse
Ubuntu