PT-2023-26092 · Giflib · Giflib

Thomas Bernard

·

Published

2023-07-19

·

Updated

2023-07-28

·

CVE-2023-37748

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ngiflib version 5e7292
Description The issue is related to an infinite loop in the DecodeGifImg function at ngiflib.c. This function is part of the ngiflib commit 5e7292.
Recommendations For ngiflib version 5e7292, consider disabling the DecodeGifImg function as a temporary workaround until a patch is available.

Exploit

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2023-37748

Affected Products

Giflib