Vulnerability Description
libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.
CVSS Score
2.6
LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libungif | Libungif | <= 4.1 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=109997
- http://scary.beasts.org/security/CESA-2005-007.txt
- http://secunia.com/advisories/17436
- http://secunia.com/advisories/17438
- http://secunia.com/advisories/17442
- http://secunia.com/advisories/17462
- http://secunia.com/advisories/17482
- http://secunia.com/advisories/17488
- http://secunia.com/advisories/17497
- http://secunia.com/advisories/17508
- http://secunia.com/advisories/17559
- http://secunia.com/advisories/34872
- http://secunia.com/advisories/35164
- http://securitytracker.com/id?1015149
- http://sourceforge.net/project/shownotes.php?release_id=364493
FAQ
What is CVE-2005-2974?
CVE-2005-2974 is a vulnerability with a CVSS score of 2.6 (LOW). libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.
How severe is CVE-2005-2974?
CVE-2005-2974 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2974?
Check the references section above for vendor advisories and patch information. Affected products include: Libungif Libungif.