A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
History

Wed, 18 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
Title Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-200
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-06-17T14:30:42.665Z

Updated: 2025-06-17T14:43:23.322Z

Reserved: 2025-06-17T11:58:17.009Z

Link: CVE-2025-6199

cve-icon Vulnrichment

Updated: 2025-06-17T14:43:16.070Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T15:15:54.307

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-6199

cve-icon Redhat

Severity : Low

Publid Date: 2025-06-17T00:00:00Z

Links: CVE-2025-6199 - Bugzilla