An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libgsf-develUpgrade libgsf-debuginfoUpgrade libgsf | Nov 4, 2024 | Oct 3, 2024 |
| Debian | — | Upgrade libgsf | Oct 7, 2024 | Oct 3, 2024 |
| Gentoo Linux | — | Upgrade gnome-extra/libgsf. | Jan 24, 2025 | Oct 3, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgsf | Jan 21, 2025 | Oct 3, 2024 |
| Suse | — | Upgrade typelib-1_0-Gsf-1Upgrade libgsf-develUpgrade libgsf-toolsUpgrade libgsf-langUpgrade libgsf-1-114Upgrade libgsf-1-114-32bitUpgrade gsf-office-thumbnailer | Dec 5, 2025 | Oct 29, 2024 |
| Ubuntu | — | Upgrade libgsf-1-114 | Oct 11, 2024 | Oct 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub