Unrated severityNVD Advisory· Published Dec 26, 2020· Updated Aug 4, 2024
CVE-2020-29385
CVE-2020-29385
Description
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.
Affected products
5- GNOME/gdk-pixbufdescription
- osv-coords4 versionspkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2
< 2.40.0-lp152.2.3.1+ 3 more
- (no CPE)range: < 2.40.0-lp152.2.3.1
- (no CPE)range: < 2.42.6-3.2
- (no CPE)range: < 2.40.0-3.3.1
- (no CPE)range: < 2.40.0-3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BGZVCTH5O7WBJLYXZ2UOKLYNIFPVR55D/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EANWYODLOJDFLMBH6WEKJJMQ5PKLEWML/mitrevendor-advisoryx_refsource_FEDORA
- bugs.debian.org/cgi-bin/bugreport.cgimitrex_refsource_CONFIRM
- gitlab.gnome.org/GNOME/gdk-pixbuf/-/blob/master/NEWSmitrex_refsource_MISC
- gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/164mitrex_refsource_CONFIRM
- security.gentoo.org/glsa/202012-15mitrex_refsource_MISC
- ubuntu.com/security/CVE-2020-29385mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.