An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-libgsfamazon-linux-ami-2-upgrade-libgsf-debuginfoamazon-linux-ami-2-upgrade-libgsf-devel | Nov 4, 2024 | Oct 3, 2024 | |
| Debian | debian-upgrade-libgsf | Oct 7, 2024 | Oct 3, 2024 | |
| Gentoo Linux | gentoo-linux-upgrade-gnome-extra-libgsf | Jan 24, 2025 | Oct 3, 2024 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-libgsf | Jan 21, 2025 | Oct 3, 2024 | |
| Suse | — | suse-upgrade-gsf-office-thumbnailersuse-upgrade-libgsf-1-114suse-upgrade-libgsf-1-114-32bitsuse-upgrade-libgsf-develsuse-upgrade-libgsf-langsuse-upgrade-libgsf-toolssuse-upgrade-typelib-1_0-gsf-1 | Dec 5, 2025 | Oct 29, 2024 |
| Ubuntu | ubuntu-upgrade-libgsf-1-114 | Oct 11, 2024 | Oct 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub