PT-2023-29303 · Gifsicle+2 · Gifsicle+2

Song Jiaxuan

+1

·

Published

2023-10-09

·

Updated

2025-11-04

·

CVE-2023-44821

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gifsicle versions 1.92 through 1.94
Description The issue might allow a denial of service due to memory consumption if Gifsicle is deployed in a way that allows untrusted input to affect Gif Realloc calls. However, this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation and does not have realistic use cases in which an adversary controls the entire command line. A buffer overflow vulnerability via the --crop parameter in the command line parameters could also lead to a denial of service.
Recommendations For Gifsicle versions 1.92 through 1.94, consider restricting the use of the --crop parameter in the command line to minimize the risk of exploitation. As a temporary workaround, avoid using Gifsicle in scenarios where untrusted input could affect Gif Realloc calls until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11513
ALT-PU-2024-6946
ALT-PU-2024-6948
ALT-PU-2025-1450
CVE-2023-44821

Affected Products

Alt Linux
Debian
Gifsicle