From 8cf8fa1205da2ef4ca8f1dab049a13a46e4a4c86 Mon Sep 17 00:00:00 2001 From: Thomas Hurst Date: Sun, 29 Oct 2023 17:09:25 +0000 Subject: [PATCH] security/vuxml: Add optipng <= 0.7.7 buffer overflow Security: CVE-2023-43907 --- security/vuxml/vuln/2023.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 7f47de9a2486..5b634eba3681 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,30 @@ + + optipng -- buffer overflow from specially-crafted GIF file + + + optipng + 0.7.7 + + + + +

NVD reports:

+
+

OptiPNG v0.7.7 was discovered to contain a global buffer overflow + via the 'buffer' variable at gifread.c.

+
+ +
+ + CVE-2023-43907 + https://nvd.nist.gov/vuln/detail/CVE-2023-43907 + + + 2023-09-20 + 2023-10-29 + +
+ zeek -- potential DoS vulnerabilities -- 2.42.0