CVE-2021-20240 is a high-severity vulnerability (CVSS 8.8) affecting gdk-pixbuf versions prior to 2.42.0, including those in Fedora and GNOME. It involves an integer wraparound leading to an out-of-bounds write when processing a specially crafted GIF image, potentially causing application crashes or remote code execution. The attack requires user interaction (e.g., opening a malicious GIF) but has low attack complexity. While the vulnerability is not listed on CISA's KEV catalog and lacks public exploit code, Metasploit modules, or significant community discussion, its potential for high impact on confidentiality, integrity, and availability warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.39.2CPE matchmatch criteria | cpe:2.3:a:gnome:gdk-pixbuf:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.