MEDIUM · 5.5

CVE-2017-6961

An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is related to the read_chunk function using the pChunk...

Vulnerability Description

An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is related to the read_chunk function using the pChunk->size value (within the PNG file) to determine the amount of memory to allocate.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Apng2Gif ProjectApng2Gif1.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-6961?

CVE-2017-6961 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is related to the read_chunk function using the pChunk...

How severe is CVE-2017-6961?

CVE-2017-6961 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-6961?

Check the references section above for vendor advisories and patch information. Affected products include: Apng2Gif Project Apng2Gif.