PT-2020-7891 · Libnsgif · Libnsgif
Hans Jerry Illikainen
·
Published
2020-02-18
·
Updated
2020-02-25
·
CVE-2015-7505
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Libnsgif version 0.1.2
Description:
The issue is a stack-based buffer overflow in the
gif next LZW function, which can be triggered by a crafted LZW stream in a GIF file. This can cause a denial of service, resulting in an application crash, or potentially allow the execution of arbitrary code.Recommendations:
For Libnsgif version 0.1.2, consider updating to a newer version that addresses this issue, as using a crafted GIF file could lead to a denial of service or code execution. If no update is available, as a temporary workaround, consider restricting the use of GIF files or implementing additional validation on LZW streams to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libnsgif