Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian 11: DSA-5228-1 Critical: gdk-pixbuf Buffer Overflow Exploit

debian
Calendar Grey September 11, 2022
Debian Logo
Enhance gdk-pixbuf to resolve several buffer overflow vulnerabilities in Debian. Consult DSA-5228-1 for details and instructions.
Several vulnerabilities were discovered in gdk-pixbuf, the GDK Pixbuf library

Summary

CVE-2021-44648

Sahil Dhar reported a heap-based buffer overflow vulnerability when
decoding the lzw compressed stream of image data, which may result
in the execution of arbitrary code or denial of service if a
malformed GIF image is processed.

CVE-2021-46829

Pedro Ribeiro reported a heap-based buffer overflow vulnerability
when compositing or clearing frames in GIF files, which may result
in the execution of arbitrary code or denial of service if a
malformed GIF image is processed.

For the stable distribution (bullseye), these problems have been fixed in
version 2.42.2+dfsg-1+deb11u1.

We recommend that you upgrade your gdk-pixbuf packages.

For the detailed security status of gdk-pixbuf please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gdk-pixbuf

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/secu...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: gdk-pixbuf
CVE ID: CVE-2021-44648 CVE-2021-46829

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here