First published: Wed Oct 14 2009(Updated: )
A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pathname specified on the command line, which might allow remote attackers to create PNG files in unintended directories via a crafted command-line argument, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Catb Gif2png | =2.5.1 | |
Catb Gif2png | =2.5.2 | |
Debian Linux | ||
Redhat Fedora | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.