
Cloud Vulnerability DB
A community-led vulnerabilities database
A heap-buffer-overflow vulnerability was discovered in libgig through 20200507. The vulnerability is tracked as CVE-2021-32294 and affects the RIFF::List::GetSubList function in RIFF.cpp at line 1151 (GitHub Issue).
The vulnerability is a heap-buffer-overflow that occurs when reading 4 bytes beyond an allocated 80-byte region at address 0x60700000de40. The issue manifests in the RIFF::List::GetSubList function when processing certain files. The vulnerability was discovered using AddressSanitizer, which detected the buffer overflow during execution of the gigextract tool (GitHub Issue).
The heap-buffer-overflow vulnerability could potentially lead to code execution or information disclosure when processing malformed input files. The issue affects the library's ability to safely handle certain file formats.
The vulnerability affects multiple versions of libgig through 20200507. The issue remains vulnerable in various Debian distributions including bullseye, bookworm, trixie, and sid (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."