CVE-2023-48161Out-of-bounds Write in Project Giflib

Severity
7.1HIGHNVD
EPSS
0.0%
top 92.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22

Description

Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

Debiangiflib_project/giflib< 5.2.2-1+1

🔴Vulnerability Details

3
OSV
CVE-2023-48161: Buffer Overflow vulnerability in GifLib Project GifLib v2023-11-22
GHSA
GHSA-rgc3-xv9w-g763: Buffer Overflow vulnerability in GifLib Project GifLib v2023-11-22
CVEList
CVE-2023-48161: Buffer Overflow vulnerability in GifLib Project GifLib v2023-11-22

📋Vendor Advisories

3
Red Hat
giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function2023-11-22
Microsoft
Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c2023-11-14
Debian
CVE-2023-48161: giflib - Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local at...2023
CVE-2023-48161 — Out-of-bounds Write in Project Giflib | cvebase