Denial of Service Vulnerability in Android GIF Drawable by Koral
CVE-2022-23435

7.5HIGH

Key Information:

Vendor
CVE Published:
19 January 2022

Summary

The Android GIF Drawable library prior to version 1.2.24 is susceptible to a denial of service due to insufficient validation of comment length in its decoding process. This vulnerability allows an attacker to exploit the library by providing excessively long comments, which can cause the application utilizing this library to become unresponsive. Users of affected versions should update to version 1.2.24 or later to mitigate this issue. For more details, refer to the upstream commits and compare the vulnerable versions at the provided GitHub links.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.