Vulnerability Description
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Giflib Project | Giflib | < 5.1.7 |
| Canonical | Ubuntu Linux | 16.04 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00008.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/4107-1/Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00008.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/4107-1/Third Party Advisory
FAQ
What is CVE-2019-15133?
CVE-2019-15133 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to ze...
How severe is CVE-2019-15133?
CVE-2019-15133 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15133?
Check the references section above for vendor advisories and patch information. Affected products include: Giflib Project Giflib, Canonical Ubuntu Linux, Debian Debian Linux.