GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gdk-pixbuf | Mar 26, 2024 | Dec 26, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 26, 2020 |
| Debian | — | Upgrade gdk-pixbuf | Jul 30, 2024 | Dec 26, 2020 |
| Gentoo Linux | — | Upgrade x11-libs/gdk-pixbuf. | Dec 29, 2020 | Dec 26, 2020 |
| Oracle Solaris | — | Upgrade library/desktop/gdk-pixbuf to version 2.39.2-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Dec 26, 2020 |
| Suse | — | Upgrade libgdk_pixbuf-2_0-0Upgrade gdk-pixbuf-query-loadersUpgrade typelib-1_0-gdkpixdata-2_0Upgrade gdk-pixbuf-develUpgrade gdk-pixbuf-langUpgrade gdk-pixbuf-thumbnailerUpgrade gdk-pixbuf-query-loaders-32bitUpgrade typelib-1_0-gdkpixbuf-2_0Upgrade libgdk_pixbuf-2_0-0-32bitUpgrade gdk-pixbuf-devel-32bit | Jan 25, 2021 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libgdk-pixbuf2.0-0 | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub