CVE-2021-46829
Summary
| CVE | CVE-2021-46829 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-24 19:15:00 UTC |
| Updated | 2023-11-07 03:40:00 UTC |
| Description | GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Merge branch 'gif-overflow' into 'master' (5398f04d) · Commits · GNOME / gdk-pixbuf · GitLab |
MISC |
gitlab.gnome.org |
|
| PoC/CVE-2021-46829.md at master · pedrib/PoC · GitHub |
MISC |
github.com |
|
| Release GdkPixbuf 2.42.8 (stable) (bca00032) · Commits · GNOME / gdk-pixbuf · GitLab |
MISC |
gitlab.gnome.org |
|
| oss-security - Re: CVE Request: heap buffer overflow in gdk-pixbuf |
MLIST |
www.openwall.com |
|
| Buffer overwrite in io-gif-animation.c composite_frame() (possibly exploitable) (#190) · Issues · GNOME / gdk-pixbuf · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] Fedora 35 Update: mingw-gdk-pixbuf-2.42.8-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: mingw-gdk-pixbuf-2.42.8-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| gif: Check for overflow when compositing or clearing frames. (!121) · Merge requests · GNOME / gdk-pixbuf · GitLab |
MISC |
gitlab.gnome.org |
|
| oss-security - CVE Request: heap buffer overflow in gdk-pixbuf |
MISC |
www.openwall.com |
|
| Debian -- Security Information -- DSA-5228-1 gdk-pixbuf |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160589 Oracle Enterprise Linux Security Update for gdk-pixbuf2 (ELSA-2023-2216)
- 181003 Debian Security Update for gdk-pixbuf (DSA 5228-1)
- 184692 Debian Security Update for gdk-pixbuf (CVE-2021-46829)
- 198889 Ubuntu Security Notification for GDK-PixBuf Vulnerability (USN-5554-1)
- 241444 Red Hat Update for gdk-pixbuf2 (RHSA-2023:2216)
- 283040 Fedora Security Update for mingw (FEDORA-2022-7254ec5e96)
- 356111 Amazon Linux Security Advisory for gdk-pixbuf2 : ALAS2023-2023-352
- 752542 SUSE Enterprise Linux Security Update for gdk-pixbuf (SUSE-SU-2022:2995-1)
- 752544 SUSE Enterprise Linux Security Update for gdk-pixbuf (SUSE-SU-2022:2996-1)
- 941010 AlmaLinux Security Update for gdk-pixbuf2 (ALSA-2023:2216)