CVE-2021-20240: Integer Underflow
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
An integer wraparound bug was found in the GIF loader of gdk-pixbuf. Given a crafted input, it will abort with a segmentation fault.
Reference:
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/132
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20240?
CVE-2021-20240 is a vulnerability in gdk-pixbuf that can lead to an out-of-bounds write and potential code execution when loading a crafted GIF image.
What is the severity of CVE-2021-20240?
CVE-2021-20240 has a severity rating of 8.8 (high).
How does CVE-2021-20240 affect GNOME gdk-pixbuf?
CVE-2021-20240 affects GNOME gdk-pixbuf versions before 2.42.0.
How does CVE-2021-20240 impact Fedora?
Fedora versions 33 and 34 are affected by CVE-2021-20240.
How can I fix CVE-2021-20240?
To fix CVE-2021-20240, update gdk-pixbuf to version 2.42.0 or later.