Vulnerability Description
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Opensuse | 13.2 |
| Giflib Project | Giflib | <= 5.1.2 |
Related Weaknesses (CWE)
References
- http://bugs.fi/fuzzing/index.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00079.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00084.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00019.html
- http://www.securityfocus.com/bid/88103
- https://bugzilla.redhat.com/show_bug.cgi?id=1325771
- https://sourceforge.net/p/giflib/bugs/87/Patch
- https://sourceforge.net/p/giflib/code/ci/ea8dbc5786862a3e16a5acfa3d24e2c2f608cd8PatchVendor Advisory
- https://usn.ubuntu.com/4107-1/
- http://bugs.fi/fuzzing/index.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00079.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00084.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00019.html
- http://www.securityfocus.com/bid/88103
- https://bugzilla.redhat.com/show_bug.cgi?id=1325771
FAQ
What is CVE-2016-3977?
CVE-2016-3977 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.
How severe is CVE-2016-3977?
CVE-2016-3977 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-3977?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Giflib Project Giflib.