#VU67161 Heap-based buffer overflow in Gnome gdk-pixbuf - CVE-2021-44648
Published: September 11, 2022
Gnome gdk-pixbuf
Gnome Development Team
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when decoding the lzw compressed stream of image data in GIF files. A remote attacker can trick the victim to open a specially crafted GIF file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/136
- https://sahildhar.github.io/blogpost/GdkPixbuf-Heap-Buffer-Overflow-in-lzw_decoder_new/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEVTOGIJITK2N5AOOLKKMDIICZDQE6CH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PEKBMOO52RXONWKB6ZKKHTVPLF6WC3KF/