安全公告详情

NS-SA-2025-0126

2025-07-25 16:49:52

简介

moderate: giflib/elfutils security update

严重级别

moderate

主题

An update for giflib/elfutils is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

giflib:
elfutils:


Security Fix(es):
giflib: A flaw was found in giflib, in the command-line tool gif2rgb. Information disclosure is possible due to a buffer overflow in the DumpScreen2RGB() function.(CVE-2022-28506)
giflib: v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.(CVE-2023-39742)
giflib: A security flaw related to buffer overflow has been identified in GifLib. This flaw allows a nearby attacker to access sensitive information through the DumpSCreen2RGB function in gif2rgb.c.(CVE-2023-48161)
giflib: bugfix
elfutils: A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it's NULL), leading to a crash or potentially exploitable behavior.(CVE-2024-25260)
elfutils: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • giflib
  • elfutils

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["giflib-5.2.2-1.zncgsl7.1.x86_64.rpm","giflib-devel-5.2.2-1.zncgsl7.1.x86_64.rpm"],"source":"giflib-5.2.2-1.zncgsl7.1.src.rpm"},{"binary":["elfutils-default-yama-scope-0.190-1.zncgsl7.5.noarch.rpm","elfutils-libs-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-libelf-devel-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-libelf-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-devel-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-debuginfod-client-devel-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-debuginfod-client-0.190-1.zncgsl7.5.x86_64.rpm","elfutils-0.190-1.zncgsl7.5.x86_64.rpm"],"source":"elfutils-0.190-1.zncgsl7.5.src.rpm"}]}]}

CVE

参考