ALT-PU-2020-3150-1
Closed vulnerabilities
Published: 2017-08-09
BDU:2018-00509
Уязвимость функции read_gif программного обеспечения для просмотра GIF-файлов gifview пакета программ для создания, редактирования и оптимизации GIF-файлов Gifsicle, позволяющая нарушителю выполнить произвольный код
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: HIGH (7.5)
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
References:
Published: 2018-01-02
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-1000421
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
Severity: HIGH (7.5)
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/kohler/gifsicle/issues/114
- https://lists.debian.org/debian-lts-announce/2018/01/msg00006.html
- https://www.debian.org/security/2018/dsa-4084
- https://github.com/kohler/gifsicle/issues/114
- https://lists.debian.org/debian-lts-announce/2018/01/msg00006.html
- https://www.debian.org/security/2018/dsa-4084