Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11490

Опубликовано: 26 мая 2018
Источник: debian

Описание

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
giflibfixed5.1.7-1experimentalpackage
giflibfixed5.1.9-1package

Примечания

  • https://github.com/pts/sam2p/issues/38

  • https://sourceforge.net/p/giflib/bugs/113/

  • https://sourceforge.net/p/giflib/code/ci/08438a5098f3bb1de23a29334af55eba663f75bd/

  • Issue was reported against sam2p but issue is in dgif_lib.c from giflib.

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
redhat
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 8.8
nvd
больше 7 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 8.8
github
больше 3 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость функции DGifDecompressLine компонента dgif_lib.c библиотеки для работы с GIF файлами GIFLIB, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании