PT-2019-14636 · Giflib · Giflib

Marsman1996

·

Published

2019-09-16

·

Updated

2024-06-06

·

CVE-2019-16346

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ngiflib version 0.4
Description The issue is a heap-based buffer overflow in the WritePixel() function in ngiflib.c when called from DecodeGifImg(), caused by mishandling deinterlacing for small pictures.
Recommendations For ngiflib version 0.4, consider disabling the WritePixel() function until a patch is available to prevent potential exploitation. Restrict the use of DecodeGifImg() to minimize the risk of heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16346

Affected Products

Giflib