Infinite loop in Gnome gdk-pixbuf - CVE-2020-29385
Published: December 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the write_indexes() function in gdk-pixbuf/lzw.c. A remote attacker can pass specially crafted GIF image to the application, consume all available CPU resources and cause denial of service conditions.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
gdk-pixbuf (Alpine package)
libgdk-pixbuf2.0-0 (Ubuntu package)
How to mitigate CVE-2020-29385
libgdk-pixbuf2.0-0 (Ubuntu package) - addressed in versions 2.40.0+dfsg-3ubuntu0.1, 2.40.0+dfsg-5ubuntu0.1