CVE-2023-39742
MediumAdvisory
Published 25 Aug 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.003
- 28th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 64
- of 17,781 indexed, latest versions
- Container images
- 58
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 64 of 17,781 indexed charts deploy, on 58 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| giflibdeb | 5.1.4-0.3~16.04, 5.1.4-0.3~16.04.1, 5.1.4-2, 5.1.4-2ubuntu0.1+5 more | 5.1.4-0.3~16.04.1+esm1, 5.1.4-2ubuntu0.1+esm1, 5.1.9-1ubuntu0.1 | 51 |
| giflibapk | 5.2.1-r2, 5.2.1-r4 | 5.2.2-r0 | 7 |
- OSV records
- ALPINE-CVE-2023-39742DEBIAN-CVE-2023-39742UBUNTU-CVE-2023-39742
- Also known as
- USN-6824-1
Charts affected
64 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| deconzjanip81-helm-chartsVerified publisher | 0.1.1 | 1 of 1See more | 10,780 |
| paperlessk8s-home-lab-repo | 11.0.1 | 1 of 1See more | 9,103 |
| home-assistantkfirfer | 0.5.4 | 1 of 1See more | 6,447 |
| chaos-meshkubeblocksVerified publisher | 2.7.2 | 1 of 4See more | 13,497 |
| tinymediamanagermedia-servarrVerified publisher | 1.6.2 | 1 of 2See more | 7,944 |
| paperless-ngxmt190502 | 7.6.14 | 1 of 4See more | 11,950 |
| smilencsaVerified publisher | 1.1.0 | 1 of 23See more | 109,294 |
| nominatimnominatim-chart | 1.3.0 | 1 of 3See more | 22,658 |
| splashntppoolVerified publisher | 1.0.4 | 1 of 1See more | 27,633 |
| paperless-ngxoli-the-devVerified publisher | 1.1.1 | 1 of 1See more | 4,626 |
| cdn-remoteopencord | 0.2.4 | 1 of 3See more | 63,223 |
| javareact-java | 0.1.0 | 1 of 1See more | 15,520 |
| paperless-ngxrtomik-helm-chartsVerified publisher | 0.0.5 | 1 of 1See more | 10,605 |
| backendsignalen | 4.24.0 | 1 of 4See more | 11,636 |
Container images carrying it
58 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 665f2f5cc548 | giflib | no fix listed | 1 |
| ghcr.io/ | ab255bea133e | giflib | no fix listed | 1 |
| ghcr.io/ | b89f83345532 | giflib | no fix listed | 1 |
| ghcr.io/ | 0250d9cb0d74 | giflib | no fix listed | 1 |
| ghcr.io/ | 8368359c8dd0 | giflib | 5.1.9-1ubuntu0.1 | 1 |
| ghcr.io/ | e65123a43ecc | giflib | no fix listed | 1 |
| quay.io/ | defc3263e0e9 | giflib | 5.2.2-r0 | 1 |
| quay.io/ | c6a934439421 | giflib | 5.1.4-0.3~16.04.1+esm1 | 1 |