CVE-2020-23922: High severity giflib project vulnerability
Published Apr 21, 2021
·Updated
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
Affected Software
2 affected components
GifLib Project GifLib<=5.1.4
Apache Bookkeeper=4.12.1
Event History
Apr 21, 2021
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23922?
The severity of CVE-2020-23922 is high with a CVSS score of 7.1.
2
What software is affected by CVE-2020-23922?
The affected software includes giflib versions up to and including 5.1.4, and Apache Bookkeeper version 4.12.1.
3
What is the vulnerability description for CVE-2020-23922?
CVE-2020-23922 is a heap-based buffer over-read vulnerability in giflib.
4
How can I fix the vulnerability in giflib?
To fix the vulnerability in giflib, update to a version higher than 5.1.4.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-23922?
The CWE ID for CVE-2020-23922 is 125.