PT-2022-6963 · Giflib+5 · Giflib+5

Rajat Aggarwal

·

Published

2022-04-25

·

Updated

2026-05-13

·

CVE-2022-28506

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GIFLIB version 5.2.1
Description The issue is related to a heap-buffer-overflow in the DumpScreen2RGB() function, located in the gif2rgb.c file of the GIFLIB library. This can allow a remote attacker to gain unauthorized access to protected information. The DumpScreen2RGB() function is vulnerable due to a buffer overflow, which can be exploited by an attacker.
Recommendations For GIFLIB version 5.2.1, consider disabling the DumpScreen2RGB() function until a patch is available to prevent potential exploitation. Restrict access to the gif2rgb.c module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

AZL-10305
AZL-34727
BDU:2023-05862
CVE-2022-28506
ECHO-B0D6-3526-4173
MGASA-2022-0275
OESA-2022-1723
OPENSUSE-SU-2024_0786-1
ROSA-SA-2024-2434
SUSE-SU-2024:0786-1
SUSE-SU-2024:2607-1
SUSE-SU-2024_2607-1
USN-6824-1

Affected Products

Debian
Giflib
Linuxmint
Red Os
Suse
Ubuntu