First published: Mon Apr 25 2022(Updated: )
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GifLib Project GifLib | =5.2.1 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
ubuntu/giflib | <5.1.4-2ubuntu0.1+ | 5.1.4-2ubuntu0.1+ |
ubuntu/giflib | <5.1.9-1ubuntu0.1 | 5.1.9-1ubuntu0.1 |
ubuntu/giflib | <5.1.9-2ubuntu0.1 | 5.1.9-2ubuntu0.1 |
ubuntu/giflib | <5.2.1-2.5ubuntu0.1 | 5.2.1-2.5ubuntu0.1 |
ubuntu/giflib | <5.1.4-0.3~16.04.1+ | 5.1.4-0.3~16.04.1+ |
debian/giflib | <=5.1.9-2<=5.2.1-2.5 | 5.2.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28506 is medium.
The affected software of CVE-2022-28506 is Giflib Project Giflib 5.2.1, Fedoraproject Fedora 35, and Fedoraproject Fedora 36.
The CWE of CVE-2022-28506 is CWE-787.
To fix CVE-2022-28506, it is recommended to update Giflib to a version that includes the security patch.
More information about CVE-2022-28506 can be found at the following references: [1] [2] [3].