Name | CVE-2021-20240 |
Description | integer underflow in the GIF loader of gdk-pixbuf via crafted input leads to segmentation fault |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
gdk-pixbuf (PTS) | stretch (security), stretch | 2.36.5-2+deb9u2 | fixed |
| buster | 2.38.1+dfsg-1 | fixed |
| bullseye, sid | 2.42.2+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
gdk-pixbuf | source | stretch | (not affected) | | | |
gdk-pixbuf | source | buster | (not affected) | | | |
gdk-pixbuf | source | (unstable) | 2.42.2+dfsg-1 | | | |
Notes
[buster] - gdk-pixbuf <not-affected> (Vulnerable code introduced later)
[stretch] - gdk-pixbuf <not-affected> (Vulnerable code added later)
https://bugzilla.redhat.com/show_bug.cgi?id=1926787
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/132
Vulnerable code introduced in https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4e7b5345d2fc8f0d1dee93d8ba9ab805bc95d42f (2.39.2)
Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/086e8adf4cc352cd11572f96066b001b545f354e (2.42.0)