PT-2005-1063 · Red Hat · Red Hat

Chris Evans

·

Publicado

2005-11-03

·

Atualizado

2018-10-19

·

CVE-2005-3350

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libungif library versions prior to 4.1.0 giflib versions 4.1.3 libungif-progs versions 4.1.0 and 4.1.3 libungif-devel versions 4.1.0 and 4.1.3 giflib-devel version 4.1.3 giflib-utils version 4.1.3
Description The issue concerns multiple vulnerabilities in the libungif library and related packages in Red Hat Enterprise Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities allow attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.
Recommendations For libungif library versions prior to 4.1.0, update to version 4.1.0 or later. For giflib versions 4.1.3, consider disabling the use of GIF files until a patch is available. For libungif-progs versions 4.1.0 and 4.1.3, restrict access to the vulnerable packages to minimize the risk of exploitation. For libungif-devel versions 4.1.0 and 4.1.3, avoid using the vulnerable development libraries until the issue is resolved. For giflib-devel version 4.1.3, consider disabling the development library until a patch is available. For giflib-utils version 4.1.3, restrict access to the vulnerable utilities to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-06183
BDU:2015-06184
BDU:2015-06185
BDU:2015-06346
BDU:2015-06347
BDU:2015-06348
BDU:2015-06349
BDU:2015-06350
BDU:2015-06351
CVE-2005-3350
DSA-890-1
RHSA-2005:828
RHSA-2005_828
RHSA-2009:0444
RHSA-2009_0444

Produtos afetados

Red Hat