PT-2011-1649 · Gif2Apng · Gif2Apng

Kurt Seifried

·

Published

2011-01-14

·

Updated

2017-08-17

·

CVE-2010-4694

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gif2png versions 2.5.3 and earlier
Description A buffer overflow issue exists in the gif2png.c file of gif2png, potentially allowing attackers to cause a denial of service (application crash) or have other unspecified impacts. This can occur when processing a GIF file containing many images, resulting in long extensions for PNG output files, such as .p100. The issue can be exploited through a CGI program that launches gif2png.
Recommendations For gif2png versions 2.5.3 and earlier, update to a version later than 2.5.3 to resolve the issue. As a temporary workaround, consider restricting the use of gif2png with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4694

Affected Products

Gif2Apng