PT-2011-1649 · Gif2Apng · Gif2Apng
Kurt Seifried
·
Published
2011-01-14
·
Updated
2017-08-17
·
CVE-2010-4694
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
gif2png versions 2.5.3 and earlier
Description
A buffer overflow issue exists in the gif2png.c file of gif2png, potentially allowing attackers to cause a denial of service (application crash) or have other unspecified impacts. This can occur when processing a GIF file containing many images, resulting in long extensions for PNG output files, such as .p100. The issue can be exploited through a CGI program that launches gif2png.
Recommendations
For gif2png versions 2.5.3 and earlier, update to a version later than 2.5.3 to resolve the issue. As a temporary workaround, consider restricting the use of gif2png with untrusted input to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gif2Apng