PT-2020-7891 · Libnsgif · Libnsgif

Hans Jerry Illikainen

·

Published

2020-02-18

·

Updated

2020-02-25

·

CVE-2015-7505

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Libnsgif version 0.1.2
Description: The issue is a stack-based buffer overflow in the gif next LZW function, which can be triggered by a crafted LZW stream in a GIF file. This can cause a denial of service, resulting in an application crash, or potentially allow the execution of arbitrary code.
Recommendations: For Libnsgif version 0.1.2, consider updating to a newer version that addresses this issue, as using a crafted GIF file could lead to a denial of service or code execution. If no update is available, as a temporary workaround, consider restricting the use of GIF files or implementing additional validation on LZW streams to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7505

Affected Products

Libnsgif