PT-2023-29303 · Gifsicle+2 · Gifsicle+2

Song Jiaxuan

+1

·

Publicado

2023-10-09

·

Atualizado

2025-11-04

·

CVE-2023-44821

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gifsicle versions 1.92 through 1.94
Description The issue might allow a denial of service due to memory consumption if Gifsicle is deployed in a way that allows untrusted input to affect Gif Realloc calls. However, this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation and does not have realistic use cases in which an adversary controls the entire command line. A buffer overflow vulnerability via the --crop parameter in the command line parameters could also lead to a denial of service.
Recommendations For Gifsicle versions 1.92 through 1.94, consider restricting the use of the --crop parameter in the command line to minimize the risk of exploitation. As a temporary workaround, avoid using Gifsicle in scenarios where untrusted input could affect Gif Realloc calls until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Leak

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-11513
ALT-PU-2024-6946
ALT-PU-2024-6948
ALT-PU-2025-1450
CVE-2023-44821

Produtos afetados

Alt Linux
Debian
Gifsicle