CVE-2021-40633: High severity giflib project vulnerability
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-40633?
CVE-2021-40633 is a memory leak vulnerability in gif2rgb in giflib 5.1.4 that can allow remote attackers to trigger an out of memory exception or denial of service via a gif format file.
What is the severity of CVE-2021-40633?
CVE-2021-40633 has a severity rating of 8.8, which is considered high.
How does CVE-2021-40633 affect giflib?
CVE-2021-40633 affects giflib 5.1.4, causing a memory leak in gif2rgb.
How can remote attackers exploit CVE-2021-40633?
Remote attackers can exploit CVE-2021-40633 by sending a specially crafted gif format file to trigger an out of memory exception or denial of service.
Is there a fix for CVE-2021-40633?
Yes, updating to a version of giflib that is not affected by the vulnerability (5.1.5 or later) will resolve CVE-2021-40633.