Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3977

Опубликовано: 21 апр. 2016
Источник: debian

Описание

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
giflibfixed5.1.4-3package
giflibno-dsawheezypackage

Примечания

  • https://sourceforge.net/p/giflib/bugs/87/

  • https://sourceforge.net/p/giflib/code/ci/ea8dbc5786862a3e16a5acfa3d24e2c2f608cd88/

  • The issue was originally fixed in 5.1.4-0.3 but then the NMU upload

  • 5.1.4-0.4 just dropped the patch claiming the patch was already present

  • which is untrue and reopening the issue.

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

redhat
почти 10 лет назад

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

CVSS3: 5.5
nvd
почти 10 лет назад

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

suse-cvrf
почти 10 лет назад

Security update for giflib

suse-cvrf
почти 10 лет назад

Security update for giflib