CVE-2017-18120: Double Free
A double-free bug in the readgif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because lastname is mishandled, a different vulnerability than CVE-2017-1000421.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this bug?
The vulnerability ID of this bug is CVE-2017-18120.
What is the severity level of CVE-2017-18120?
The severity level of CVE-2017-18120 is high with a CVSS score of 7.8.
What is the affected software?
The affected software is Gifsicle version 1.90.
What is the impact of CVE-2017-18120?
CVE-2017-18120 can cause a denial-of-service attack or unspecified other impact via a maliciously crafted file.
Are there any references related to CVE-2017-18120?
Yes, you can refer to the following links for more information: [Reference 1](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739), [Reference 2](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120), [Reference 3](https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f909).