PT-2017-3583 · Gifsicle+2 · Gifsicle+2

Junxzm1990

·

Published

2017-08-09

·

Updated

2024-03-13

·

CVE-2017-1000421

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Gifsicle versions 1.89 and older
Description: The issue is related to a use-after-free in the read gif function, which can potentially lead to code execution. This is due to the improper use of memory after it has been freed, allowing a remote attacker to execute arbitrary code.
Recommendations: For Gifsicle versions 1.89 and older, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3150
ALT-PU-2020-3169
ALT-PU-2022-2491
ALT-PU-2024-3605
BDU:2018-00509
CVE-2017-1000421
DLA-1233-1
DSA-4084-1
MGASA-2018-0086
USN-4803-1

Affected Products

Alt Linux
Gifsicle
Ubuntu