UbuntuUpdates.org

Package "giflib"

Name: giflib

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • library for GIF images (development)
  • library for GIF images (library)

Latest version: 5.1.9-1ubuntu0.1
Release: focal (20.04)
Level: security
Repository: main

Links



Other versions of "giflib" in Focal

Repository Area Version
base main 5.1.9-1
base universe 5.1.9-1
security universe 5.1.9-1ubuntu0.1
updates main 5.1.9-1ubuntu0.1
updates universe 5.1.9-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 5.1.9-1ubuntu0.1 2024-06-10 15:07:02 UTC

  giflib (5.1.9-1ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2021-40633.patch: Clean up memory better at end
      of run (CVE-2021-40633)
    - debian/patches/CVE-2023-39742.patch: Fix SourceForge bug #153,
      segfault in getarg.c
    - CVE-2021-40633
    - CVE-2023-39742
  * SECURITY UPDATE: Heap buffer overflow
    - debian/patches/CVE-2022-28506.patch: Fix heap-buffer overflow
    - CVE-2022-28506

 -- Giampaolo Fresi Roglia <email address hidden> Thu, 06 Jun 2024 13:50:06 +0200

CVE-2021-40633 A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of se
CVE-2023-39742 giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.
CVE-2022-28506 There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.



About   -   Send Feedback to @ubuntu_updates