Bugzilla – Bug 1198965
VUL-1: CVE-2022-1507: chafa: NULL Pointer Dereference in function gif_internal_decode_frame
Last modified: 2022-06-23 19:15:40 UTC
CVE-2022-1507 chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1507 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1507 https://github.com/hpjansson/chafa/commit/e4b777c7b7c144cd16a0ea96108267b1004fe6c9 https://huntr.dev/bounties/104d8c5d-cac5-4baa-9ac9-291ea0bcab95
Affected: - openSUSE:Backports:SLE-15-SP3/chafa 1.4.1 - openSUSE:Backports:SLE-15-SP4/chafa 1.8.0 Not Affected: - openSUSE:Factory/chafa 1.10.2
openSUSE_Backports_SLE-15-SP3 SR#973604 openSUSE_Backports_SLE-15-SP4 SR#973605
This is an autogenerated message for OBS integration: This bug (1198965) was mentioned in https://build.opensuse.org/request/show/973604 Backports:SLE-15-SP3 / chafa https://build.opensuse.org/request/show/973605 Backports:SLE-15-SP4 / chafa
openSUSE-SU-2022:10025-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1198965 CVE References: CVE-2022-1507 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): chafa-1.4.1-bp153.2.3.1