Denial of Service Vulnerability in Android GIF Drawable by Koral
CVE-2022-23435
7.5HIGH
Summary
The Android GIF Drawable library prior to version 1.2.24 is susceptible to a denial of service due to insufficient validation of comment length in its decoding process. This vulnerability allows an attacker to exploit the library by providing excessively long comments, which can cause the application utilizing this library to become unresponsive. Users of affected versions should update to version 1.2.24 or later to mitigate this issue. For more details, refer to the upstream commits and compare the vulnerable versions at the provided GitHub links.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved