A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 21 Aug 2025 01:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Gnome Gnome gdkpixbuf | |
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gnome:gdkpixbuf:2.0.0:-:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | |
| Vendors & Products | Gnome Gnome gdkpixbuf | 
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 18 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Tue, 17 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 17 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image. | |
| Title | Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder | |
| First Time appeared | Redhat Redhat enterprise Linux | |
| Weaknesses | CWE-200 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 | |
| Vendors & Products | Redhat Redhat enterprise Linux | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2025-06-17T14:30:42.665Z
Updated: 2025-09-03T02:12:32.297Z
Reserved: 2025-06-17T11:58:17.009Z
Link: CVE-2025-6199
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-17T14:43:16.070Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-17T15:15:54.307
Modified: 2025-08-21T01:16:43.190
Link: CVE-2025-6199
 Redhat
                        Redhat