CVE-2018-11490: Buffer Overflow
Last updated 25 August 2025
Other sources
The DGifDecompressLine function in dgiflib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11490?
CVE-2018-11490 is a vulnerability in GIFLIB, possibly version 3.0.x, as later shipped in sam2p 0.49.4, that allows a heap-based buffer overflow and can lead to denial of service or other unspecified impacts.
What is the severity of CVE-2018-11490?
CVE-2018-11490 has a severity rating of 8.8 (high).
How does CVE-2018-11490 affect software?
CVE-2018-11490 affects the giflib package with versions 5.1.4-3+deb10u1, 5.1.9-2, and 5.2.1-2.5 on Debian, and 5.1.4-2ubuntu0.1 on Ubuntu 18.04 (bionic) and 5.1.4-3ubuntu0.1 on Ubuntu 19.04 (disco).
How can I fix CVE-2018-11490 on Debian?
To fix CVE-2018-11490 on Debian, update the giflib package to version 5.1.4-3+deb10u1 or higher.
How can I fix CVE-2018-11490 on Ubuntu?
To fix CVE-2018-11490 on Ubuntu 18.04 (bionic), update the giflib package to version 5.1.4-2ubuntu0.1 or higher. To fix it on Ubuntu 19.04 (disco), update the giflib package to version 5.1.4-3ubuntu0.1 or higher.