android-gif-drawable vulerable to denial of service due to unrestricted comment length
High severity
GitHub Reviewed
Published
Jan 20, 2022
to the GitHub Advisory Database
•
Updated Jan 13, 2025
Package
Affected versions
< 1.2.24
Patched versions
1.2.24
Description
Published by the National Vulnerability Database
Jan 19, 2022
Published to the GitHub Advisory Database
Jan 20, 2022
Reviewed
Jan 13, 2025
Last updated
Jan 13, 2025
decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.
References