GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gir1.2-gdkpixbuf-2.0",
"binary_version": "2.40.0+dfsg-3ubuntu0.3"
},
{
"binary_name": "libgdk-pixbuf2.0-0",
"binary_version": "2.40.0+dfsg-3ubuntu0.3"
},
{
"binary_name": "libgdk-pixbuf2.0-bin",
"binary_version": "2.40.0+dfsg-3ubuntu0.3"
},
{
"binary_name": "libgdk-pixbuf2.0-common",
"binary_version": "2.40.0+dfsg-3ubuntu0.3"
},
{
"binary_name": "libgdk-pixbuf2.0-dev",
"binary_version": "2.40.0+dfsg-3ubuntu0.3"
}
]
}