2020-11-30 16:01:49 +00:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
2020-12-26 02:02:16 +00:00
"ID" : "CVE-2020-29385" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
2020-11-30 16:01:49 +00:00
} ,
2020-12-26 02:02:16 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2020-11-30 16:01:49 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-12-26 02:02:16 +00:00
"value" : "GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"url" : "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/blob/master/NEWS" ,
"refsource" : "MISC" ,
"name" : "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/blob/master/NEWS"
} ,
{
"refsource" : "MISC" ,
"name" : "https://security.gentoo.org/glsa/202012-15" ,
"url" : "https://security.gentoo.org/glsa/202012-15"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977166" ,
"url" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977166"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://ubuntu.com/security/CVE-2020-29385" ,
"url" : "https://ubuntu.com/security/CVE-2020-29385"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/164" ,
"url" : "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/164"
2021-02-23 02:00:39 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-2e59756cbe" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EANWYODLOJDFLMBH6WEKJJMQ5PKLEWML/"
2021-03-15 03:00:41 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-755ba8968a" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP/"
2021-03-19 23:00:39 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-c918632e13" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BGZVCTH5O7WBJLYXZ2UOKLYNIFPVR55D/"
2020-11-30 16:01:49 +00:00
}
]
}
}