PT-2005-1062 · Red Hat · Red Hat

Chris Evans

·

Published

2005-11-03

·

Updated

2023-02-13

·

CVE-2005-2974

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libungif library versions prior to 4.1.0 giflib versions 4.1.3 and earlier libungif-progs versions 4.1.3 and earlier libungif-devel versions 4.1.3 and earlier giflib-devel versions 4.1.3 and earlier libungif-progs versions 4.1.0 and earlier libungif-devel versions 4.1.0 and earlier
Description The issue concerns multiple vulnerabilities in the libungif library and related packages in Red Hat Enterprise Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to the information, attackers can cause a denial of service via a crafted GIF file that triggers a null dereference.
Recommendations For libungif library versions prior to 4.1.0, update to version 4.1.0 or later. For giflib versions 4.1.3 and earlier, update to a version later than 4.1.3. For libungif-progs versions 4.1.3 and earlier, update to a version later than 4.1.3. For libungif-devel versions 4.1.3 and earlier, update to a version later than 4.1.3. For giflib-devel versions 4.1.3 and earlier, update to a version later than 4.1.3. For libungif-progs versions 4.1.0 and earlier, update to version 4.1.0 or later. For libungif-devel versions 4.1.0 and earlier, update to version 4.1.0 or later.

Fix

Related Identifiers

BDU:2015-06183
BDU:2015-06184
BDU:2015-06185
BDU:2015-06346
BDU:2015-06347
BDU:2015-06348
BDU:2015-06349
BDU:2015-06350
BDU:2015-06351
CVE-2005-2974
DSA-890-1
RHSA-2005:828
RHSA-2005_828
RHSA-2009:0444
RHSA-2009_0444

Affected Products

Red Hat