REDHAT-BUG-2260545: Medium severity gnome gdkpixbuf vulnerability
In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in aniloadchunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdkpixbufsetoption() in gdk-pixbuf.c.
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/202
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2260545?
REDHAT-BUG-2260545 is classified as a critical vulnerability due to potential heap memory corruption.
How do I fix REDHAT-BUG-2260545?
To fix REDHAT-BUG-2260545, upgrade your GNOME GdkPixbuf to version 2.42.10 or later.
What types of attacks can REDHAT-BUG-2260545 enable?
REDHAT-BUG-2260545 can enable remote code execution or denial of service attacks through crafted ANI files.
Which versions of GNOME GdkPixbuf are affected by REDHAT-BUG-2260545?
Versions of GNOME GdkPixbuf up to and including 2.42.10 are affected by REDHAT-BUG-2260545.
What is the impact of exploiting REDHAT-BUG-2260545?
Exploiting REDHAT-BUG-2260545 could lead to heap metadata corruption and potentially disrupt system functionality.