CVE-2020-23922

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
giflib_projectgiflib
𝑥
≤ 5.1.4
apachebookkeeper
4.12.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
giflib
bookworm
unimportant
bullseye
unimportant
sid
5.2.2-1
fixed
trixie
5.2.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
giflib
bionic
not-affected
focal
not-affected
groovy
ignored
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
not-affected
trusty
dne
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
giflib
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed
giflib-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed
giflib-debugsource
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed
giflib-devel
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed
giflib-utils
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed
giflib-utils-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023
fixed