First published: Wed Apr 21 2021(Updated: )
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GifLib Project GifLib | <=5.1.4 | |
Apache Bookkeeper | =4.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-23922 is high with a CVSS score of 7.1.
The affected software includes giflib versions up to and including 5.1.4, and Apache Bookkeeper version 4.12.1.
CVE-2020-23922 is a heap-based buffer over-read vulnerability in giflib.
To fix the vulnerability in giflib, update to a version higher than 5.1.4.
The CWE ID for CVE-2020-23922 is 125.