Vulnerability Description
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miniupnp Project | Ngiflib | 0.4 |
Related Weaknesses (CWE)
References
- https://github.com/miniupnp/ngiflib/commit/b588a2249c7abbfc52173e32ee11d6facef82Patch
- https://github.com/miniupnp/ngiflib/issues/1ExploitThird Party Advisory
- https://github.com/miniupnp/ngiflib/commit/b588a2249c7abbfc52173e32ee11d6facef82Patch
- https://github.com/miniupnp/ngiflib/issues/1ExploitThird Party Advisory
FAQ
What is CVE-2018-10677?
CVE-2018-10677 is a vulnerability with a CVSS score of 8.8 (HIGH). The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer ...
How severe is CVE-2018-10677?
CVE-2018-10677 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10677?
Check the references section above for vendor advisories and patch information. Affected products include: Miniupnp Project Ngiflib.