Buffer overflow in GIFLIB - CVE-2023-39742

 

Buffer overflow in GIFLIB - CVE-2023-39742

Published: September 18, 2023 / Updated: March 7, 2024


Vulnerability identifier: #VU80867
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39742
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in getarg.c. A remote attacker can pass a specially crafted input to the application, trigger memory corruption and perform a denial of service (DoS) attack.


Affected software

GIFLIB
Amazon Linux AMI
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Ubuntu
openEuler
Anolis OS
Fedora
giflib-tools (Ubuntu package)
libgif6-32bit
libgif6-debuginfo-32bit
libgif6-debuginfo
libgif6
giflib-progs-debuginfo
giflib-progs
giflib-debugsource
giflib-devel
giflib-utils
giflib
giflib-help
giflib-debuginfo

How to mitigate CVE-2023-39742

Install update from vendor's website.

GIFLIB - update to 5.2.2
giflib-tools (Ubuntu package) - addressed in versions Ubuntu Pro, 5.1.9-1ubuntu0.1, 5.1.9-2ubuntu0.1, 5.2.1-2.5ubuntu0.1
libgif6-32bit - update to 5.0.5-13.6.1
libgif6-debuginfo-32bit - update to 5.0.5-13.6.1
libgif6-debuginfo - update to 5.0.5-13.6.1
libgif6 - update to 5.0.5-13.6.1
giflib-progs-debuginfo - update to 5.0.5-13.6.1
giflib-progs - update to 5.0.5-13.6.1
giflib-debugsource - update to 5.0.5-13.6.1
giflib-devel - update to 5.0.5-13.6.1
giflib-utils - update to 5.2.1-4
giflib-devel - update to 5.2.1-4
giflib - update to 5.2.1-4
giflib-help - update to 5.2.1-4
giflib-debugsource - update to 5.2.1-4
giflib-utils - update to 5.2.1-4
giflib-debuginfo - update to 5.2.1-4
giflib-devel - update to 5.2.1-4
giflib - update to 5.2.1-4
giflib - update to 5.2.1-9
giflib - addressed in versions 5.2.1-17.fc37, 5.2.1-17.fc38, 5.2.1-17.fc39

External References

Related Security Bulletins