CVE-2022-23435: High severity android-gif-drawable vulnerability
decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23435?
CVE-2022-23435 is a vulnerability in android-gif-drawable before 1.2.24 that allows denial of service by not limiting the maximum length of a comment.
How can I determine if my system is affected by CVE-2022-23435?
Check if you have android-gif-drawable version 1.2.23 or earlier installed on your system.
How severe is CVE-2022-23435?
CVE-2022-23435 has a severity score of 7.5, indicating a high severity.
How can I fix CVE-2022-23435?
Update android-gif-drawable to version 1.2.24 or later.
Where can I find more information about CVE-2022-23435?
You can find more information about CVE-2022-23435 at the following references: [Github commit](https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887), [Github comparison](https://github.com/koral--/android-gif-drawable/compare/v1.2.23...v1.2.24)