CVE-2018-10677: Buffer Overflow
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10677?
CVE-2018-10677 has a medium severity level due to its potential to cause a denial of service and application crash.
How do I fix CVE-2018-10677?
To fix CVE-2018-10677, upgrade to a patched version of ngiflib that contains necessary checks and protections against malicious GIF files.
What vulnerability does CVE-2018-10677 exploit?
CVE-2018-10677 exploits a heap-based buffer overflow in the DecodeGifImg function, which can be triggered by specially crafted GIF files.
Which software is affected by CVE-2018-10677?
CVE-2018-10677 specifically affects MiniUPnP ngiflib version 0.4.
What impact can be caused by CVE-2018-10677?
CVE-2018-10677 can lead to denial of service through application crashes or potentially allow other unspecified impacts.