First published: Sun Jul 24 2022(Updated: )
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME gdk-pixbuf | <2.42.8 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =11.0 | |
debian/gdk-pixbuf | 2.38.1+dfsg-1 2.42.2+dfsg-1+deb11u1 2.42.10+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46829 is a heap-based buffer overflow vulnerability in GNOME GdkPixbuf before version 2.42.8, which can be abused for code execution.
The vulnerability occurs when compositing or clearing frames in GIF files using GdkPixbuf in GNOME.
The severity of CVE-2021-46829 is high, with a CVSS score of 7.8.
GNOME GdkPixbuf versions before 2.42.8 are affected, as well as Fedora 35 and Debian Linux 11.0.
To fix CVE-2021-46829, users should update to GDK-PixBuf version 2.42.8 or later.