First published: Wed Jan 19 2022(Updated: )
decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android-gif-drawable Project Android-gif-drawable | <1.2.24 |
https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23435 is a vulnerability in android-gif-drawable before 1.2.24 that allows denial of service by not limiting the maximum length of a comment.
Check if you have android-gif-drawable version 1.2.23 or earlier installed on your system.
CVE-2022-23435 has a severity score of 7.5, indicating a high severity.
Update android-gif-drawable to version 1.2.24 or later.
You can find more information about CVE-2022-23435 at the following references: [Github commit](https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887), [Github comparison](https://github.com/koral--/android-gif-drawable/compare/v1.2.23...v1.2.24)