First published: Wed Apr 27 2022(Updated: )
chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Chafa | <1.10.2 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1507 has a severity rating that may lead to a denial of service due to a NULL pointer dereference.
To fix CVE-2022-1507, update the Chafa software to version 1.10.2 or later.
CVE-2022-1507 affects all versions of Chafa prior to 1.10.2.
The vulnerability in CVE-2022-1507 is caused by a NULL pointer dereference in the gif_internal_decode_frame function.
Yes, CVE-2022-1507 can be exploited remotely using a crafted input file that triggers the vulnerability.