PT-2023-29303 · Gifsicle+2 · Gifsicle+2
Song Jiaxuan
+1
·
Published
2023-10-09
·
Updated
2025-11-04
·
CVE-2023-44821
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Gifsicle versions 1.92 through 1.94
Description
The issue might allow a denial of service due to memory consumption if Gifsicle is deployed in a way that allows untrusted input to affect Gif Realloc calls. However, this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation and does not have realistic use cases in which an adversary controls the entire command line. A buffer overflow vulnerability via the
--crop parameter in the command line parameters could also lead to a denial of service.Recommendations
For Gifsicle versions 1.92 through 1.94, consider restricting the use of the
--crop parameter in the command line to minimize the risk of exploitation. As a temporary workaround, avoid using Gifsicle in scenarios where untrusted input could affect Gif Realloc calls until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Gifsicle