CVE-2019-15133: Divide by Zero
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgiflib.c if the height field of the ImageSize data structure is equal to zero.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-15133?
CVE-2019-15133 is a vulnerability in GIFLIB that triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
How does CVE-2019-15133 affect the software?
CVE-2019-15133 affects GIFLIB before 2019-02-16 and can cause a divide-by-zero exception.
What is the severity of CVE-2019-15133?
CVE-2019-15133 has a severity score of 6.5, which is considered medium.
How can I fix CVE-2019-15133?
To fix CVE-2019-15133, update GIFLIB to versions 5.1.4-3+deb10u1, 5.1.9-2, or 5.2.1-2.5.
Where can I find more information about CVE-2019-15133?
More information about CVE-2019-15133 can be found at the following references: [CVE-2019-15133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15133), [OSS-Fuzz Issue 13008](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008), [GIFLIB Bug 119](https://sourceforge.net/p/giflib/bugs/119/)