PT-2019-14636 · Giflib · Giflib

Marsman1996

·

Publicado

2019-09-16

·

Atualizado

2024-06-06

·

CVE-2019-16346

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ngiflib version 0.4
Description The issue is a heap-based buffer overflow in the WritePixel() function in ngiflib.c when called from DecodeGifImg(), caused by mishandling deinterlacing for small pictures.
Recommendations For ngiflib version 0.4, consider disabling the WritePixel() function until a patch is available to prevent potential exploitation. Restrict the use of DecodeGifImg() to minimize the risk of heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16346

Produtos afetados

Giflib