An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libgsfUpgrade libgsf-develUpgrade libgsf-debuginfo | Nov 4, 2024 | Oct 3, 2024 |
| Debian | — | Upgrade libgsf | Oct 7, 2024 | Oct 3, 2024 |
| Gentoo Linux | — | Upgrade gnome-extra/libgsf. | Jan 24, 2025 | Oct 3, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgsf | Jan 21, 2025 | Oct 3, 2024 |
| Suse | — | Upgrade gsf-office-thumbnailerUpgrade libgsf-1-114-32bitUpgrade libgsf-1-114Upgrade libgsf-toolsUpgrade typelib-1_0-Gsf-1Upgrade libgsf-langUpgrade libgsf-devel | Dec 5, 2025 | Oct 29, 2024 |
| Ubuntu | — | Upgrade libgsf-1-114 | Oct 11, 2024 | Oct 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub