CVE-2020-19752: Null Pointer Dereference
Published Sep 7, 2021
·Updated
The findcolororerror function in gifsicle 1.92 contains a NULL pointer dereference.
Affected Software
4 affected components
Lcdf Gifsicle=1.92
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Gifsicle Project Gifsicle=1.92
Remediation
Patch Available
Event History
Sep 7, 2021
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
Description
Frequently Asked Questions
1
What is CVE-2020-19752?
CVE-2020-19752 is a vulnerability in the find_color_or_error function in gifsicle 1.92 that contains a NULL pointer dereference.
2
How severe is CVE-2020-19752?
CVE-2020-19752 has a severity rating of high with a CVSS score of 7.5.
3
What software is affected by CVE-2020-19752?
The affected software includes gifsicle version 1.92, Fedora versions 33 and 34, and lcdf gifsicle version 1.92.
4
How can I fix CVE-2020-19752?
To fix CVE-2020-19752, update gifsicle to a version that includes the fix or apply the relevant patch provided by the vendor.
5
Where can I find more information about CVE-2020-19752?
You can find more information about CVE-2020-19752 at the following references: [link1], [link2], [link3].