First published: Sat May 26 2018(Updated: )
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GifLib Project GifLib | >=3.0<=3.1.1 | |
Sam2p Project Sam2p | =0.49.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-11489.
The severity level of CVE-2018-11489 is high with a score of 8.8.
CVE-2018-11489 affects GIFLIB versions between 3.0 and 3.1.1, and sam2p version 0.49.4.
CVE-2018-11489 can lead to a denial of service or other unspecified impact due to a heap-based buffer overflow.
Yes, you can find references for CVE-2018-11489 at the following links: [1] http://www.securityfocus.com/bid/104341, [2] https://github.com/pts/sam2p/issues/37, [3] https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E