PT-2024-5877 · Unknown+10 · Gdk-Pixbuf+10

Published

2024-01-26

·

Updated

2025-05-06

·

CVE-2022-48622

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GdkPixbuf versions through 2.42.10
Description The issue is related to heap memory corruption in the ANI decoder when parsing chunks in a crafted .ani file. This corruption can occur in the ani load chunk function and may allow an attacker to overwrite heap metadata, potentially leading to a denial of service or code execution attack. The vulnerability is also related to the gdk pixbuf set option function in gdk-pixbuf.c.
Recommendations For versions through 2.42.10, consider disabling the ANI decoder or restricting the use of the ani load chunk function until a patch is available. Additionally, avoid using the gdk pixbuf set option function with crafted .ani files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2024:3341
ALSA-2024:3834
ALT-PU-2024-6917
AZL-34069
AZL-34726
BDU:2024-06670
CESA-2024_3341
CVE-2022-48622
INFSA-2024_3341
INFSA-2024_3834
MGASA-2024-0182
OESA-2024-2039
OESA-2024-2040
OESA-2024-2143
OESA-2024-2144
OESA-2024-2145
OPENSUSE-SU-2024:13967-1
OPENSUSE-SU-2024_2076-1
OPENSUSE-SU-2024_2077-1
RHSA-2024:3341
RHSA-2024:3834
RHSA-2024_3341
RHSA-2024_3834
RLSA-2024:3341
SUSE-SU-2024:1699-1
SUSE-SU-2024:1842-1
SUSE-SU-2024:2076-1
SUSE-SU-2024:2077-1
SUSE-SU-2024:2077-2
SUSE-SU-2024_1699-1
SUSE-SU-2024_1842-1
SUSE-SU-2024_2076-1
SUSE-SU-2024_2077-1
SUSE-SU-2025:20217-1
USN-6806-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Gdk-Pixbuf
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu