Vulnerability Description
libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libungif | Libungif | <= 4.1 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=109997
- http://scary.beasts.org/security/CESA-2005-007.txt
- http://secunia.com/advisories/17436
- http://secunia.com/advisories/17438
- http://secunia.com/advisories/17442
- http://secunia.com/advisories/17462
- http://secunia.com/advisories/17482
- http://secunia.com/advisories/17488
- http://secunia.com/advisories/17497
- http://secunia.com/advisories/17508
- http://secunia.com/advisories/17559
- http://secunia.com/advisories/34872
- http://secunia.com/advisories/35164
- http://securitytracker.com/id?1015149
- http://sourceforge.net/project/shownotes.php?release_id=364493
FAQ
What is CVE-2005-3350?
CVE-2005-3350 is a vulnerability with a CVSS score of 7.5 (HIGH). libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.
How severe is CVE-2005-3350?
CVE-2005-3350 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3350?
Check the references section above for vendor advisories and patch information. Affected products include: Libungif Libungif.