Vulnerability Description
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lcdf | Gifsicle | 1.90 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739Mailing ListThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120Mailing ListThird Party Advisory
- https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f9PatchThird Party Advisory
- https://github.com/kohler/gifsicle/issues/117Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739Mailing ListThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120Mailing ListThird Party Advisory
- https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f9PatchThird Party Advisory
- https://github.com/kohler/gifsicle/issues/117Third Party Advisory
FAQ
What is CVE-2017-18120?
CVE-2017-18120 is a vulnerability with a CVSS score of 7.8 (HIGH). A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, becaus...
How severe is CVE-2017-18120?
CVE-2017-18120 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18120?
Check the references section above for vendor advisories and patch information. Affected products include: Lcdf Gifsicle.