decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "android-gif-drawable/src/main/c/decoding.c" }, "deprecated": false, "digest": { "line_hashes": [ "129823501033511240129047824089354369775", "316193249013358743226091813887949898530", "60714204790306486470492009225635403660", "52123304688088156956192345558888218494", "46038213712840512898127352381227602308", "252014771493387578434026301065289782225", "22236143923408314898103502069118509635", "211131470429896384312664607067992137494", "280558655947406488351717893498674248663", "76245982527847464765038419948934828597" ], "threshold": 0.9 }, "id": "CVE-2022-23435-157ada6e", "source": "https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "android-gif-drawable/src/main/c/decoding.c", "function": "getComment" }, "deprecated": false, "digest": { "length": 481.0, "function_hash": "48138415240480838434146030969822863130" }, "id": "CVE-2022-23435-8e144436", "source": "https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887" } ] }