PT-2005-1063 · Red Hat · Red Hat

Chris Evans

·

Published

2005-11-03

·

Updated

2018-10-19

·

CVE-2005-3350

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libungif library versions prior to 4.1.0 giflib versions 4.1.3 libungif-progs versions 4.1.0 and 4.1.3 libungif-devel versions 4.1.0 and 4.1.3 giflib-devel version 4.1.3 giflib-utils version 4.1.3
Description The issue concerns multiple vulnerabilities in the libungif library and related packages in Red Hat Enterprise Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities allow attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.
Recommendations For libungif library versions prior to 4.1.0, update to version 4.1.0 or later. For giflib versions 4.1.3, consider disabling the use of GIF files until a patch is available. For libungif-progs versions 4.1.0 and 4.1.3, restrict access to the vulnerable packages to minimize the risk of exploitation. For libungif-devel versions 4.1.0 and 4.1.3, avoid using the vulnerable development libraries until the issue is resolved. For giflib-devel version 4.1.3, consider disabling the development library until a patch is available. For giflib-utils version 4.1.3, restrict access to the vulnerable utilities to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06183
BDU:2015-06184
BDU:2015-06185
BDU:2015-06346
BDU:2015-06347
BDU:2015-06348
BDU:2015-06349
BDU:2015-06350
BDU:2015-06351
CVE-2005-3350
DSA-890-1
RHSA-2005:828
RHSA-2005_828
RHSA-2009:0444
RHSA-2009_0444

Affected Products

Red Hat