PT-2011-1650 · Gif2Apng · Gif2Apng
Patroklos Argyroudis
·
Published
2011-01-14
·
Updated
2017-08-17
·
CVE-2010-4695
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
gif2png versions 2.5.1 through 2.5.2
Description
The issue allows remote attackers to create PNG files in unintended directories via a crafted command-line argument. This can be demonstrated by a CGI program that launches gif2png.
Recommendations
For gif2png versions 2.5.1 and 2.5.2, consider restricting access to the command-line interface until a patch is available. As a temporary workaround, avoid using gif2png with untrusted input.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gif2Apng