CVE-2022-28506

Severity
5.5MEDIUM
EPSS
0.1%
top 78.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateJun 10

Description

There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debiangiflib< 5.2.2-1+1
Ubuntugiflib< 5.1.9-1ubuntu0.1+3

Also affects: Fedora 35, 36

🔴Vulnerability Details

4
OSV
giflib vulnerabilities2024-06-10
GHSA
GHSA-x77v-4m7v-7fgv: There is a heap-buffer-overflow in GIFLIB 52022-04-26
OSV
CVE-2022-28506: There is a heap-buffer-overflow in GIFLIB 52022-04-25
CVEList
CVE-2022-28506: There is a heap-buffer-overflow in GIFLIB 52022-04-25

📋Vendor Advisories

4
Ubuntu
GIFLIB vulnerabilities2024-06-10
Red Hat
giflib: buffer overflow in function DumpScreen2RGB()2022-04-25
Microsoft
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.2022-04-12
Debian
CVE-2022-28506: giflib - There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif...2022
CVE-2022-28506 (MEDIUM CVSS 5.5) | There is a heap-buffer-overflow in | cvebase.io