Buffer Overflow Affecting giflib package, versions *
Threat Intelligence
EPSS
0.04% (6th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-GIFLIB-5877059
- published 31 Aug 2023
- disclosed 25 Aug 2023
Introduced: 25 Aug 2023
CVE-2023-39742 Open this link in a new tabHow to fix?
There is no fixed version for RHEL:7 giflib.
NVD Description
Note: Versions mentioned in the description apply only to the upstream giflib package and not the giflib package as distributed by RHEL.
See How to fix? for RHEL:7 relevant fixed versions and status.
giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.
References
- https://access.redhat.com/security/cve/CVE-2023-39742
- https://gist.github.com/huanglei3/ec9090096aa92445cf0a8baa8e929084
- https://sourceforge.net/p/giflib/bugs/166/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O4RLSFGPBPR3FMIUJCWPGVIYIU35YGQX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WO6WL2TCGO6T4VKGACDIVSZI74WJAU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OPNBOB65TEA4ZEPLVENI26BY4LEX7TEF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O4RLSFGPBPR3FMIUJCWPGVIYIU35YGQX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPNBOB65TEA4ZEPLVENI26BY4LEX7TEF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5WO6WL2TCGO6T4VKGACDIVSZI74WJAU/
CVSS Scores
version 3.1