First published: Sat Aug 17 2019(Updated: )
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GifLib Project GifLib | <5.1.7 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Debian Debian Linux | =10.0 | |
debian/giflib | 5.1.9-2 5.2.1-2.5 5.2.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15133 is a vulnerability in GIFLIB that triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVE-2019-15133 affects GIFLIB before 2019-02-16 and can cause a divide-by-zero exception.
CVE-2019-15133 has a severity score of 6.5, which is considered medium.
To fix CVE-2019-15133, update GIFLIB to versions 5.1.4-3+deb10u1, 5.1.9-2, or 5.2.1-2.5.
More information about CVE-2019-15133 can be found at the following references: [CVE-2019-15133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15133), [OSS-Fuzz Issue 13008](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008), [GIFLIB Bug 119](https://sourceforge.net/p/giflib/bugs/119/)