Medium severity5.5NVD Advisory· Published Apr 27, 2022· Updated Jun 17, 2026
CVE-2022-1507
CVE-2022-1507
Description
chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/chafa&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/chafa&distro=SUSE%20Package%20Hub%2015%20SP3
< 1.4.1-bp153.2.3.1+ 1 more
- (no CPE)range: < 1.4.1-bp153.2.3.1
- (no CPE)range: < 1.4.1-bp153.2.3.1
- hpjansson/hpjansson/chafav5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/hpjansson/chafa/commit/e4b777c7b7c144cd16a0ea96108267b1004fe6c9nvdPatchThird Party Advisory
- huntr.dev/bounties/104d8c5d-cac5-4baa-9ac9-291ea0bcab95nvdExploitIssue TrackingPatchThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3PLHKTQYK6AO3M5NAVM3CDVQTZZS6MCO/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIOAZPITFL2Y7Y6KHCZ4OIK7P7KWFN22/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L54UEP5S254VP5FZWGFPHLTPMFJVOGYT/nvd
News mentions
0No linked articles in our index yet.