Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11489

Опубликовано: 26 мая 2018
Источник: debian

Описание

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
giflibfixed4.1.4-1package

Примечания

  • https://github.com/pts/sam2p/issues/37

  • https://sourceforge.net/p/giflib/bugs/112/

  • Issue was reported against sam2p but issue is in dgif_lib.c from giflib.

  • https://github.com/pts/sam2p/files/2252965/sam2p_CVEs.patch.txt

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
redhat
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 8.8
nvd
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 8.8
github
больше 3 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.