CVE-2023-44821: Medium severity Lcdf Gifsicle vulnerability
DISPUTED Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect GifRealloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44821?
CVE-2023-44821 is a vulnerability in Gifsicle through version 1.94 that may allow a denial of service attack due to untrusted input affecting Gif_Realloc calls.
What is the severity of CVE-2023-44821?
The severity of CVE-2023-44821 is medium, with a severity score of 5.5.
How does CVE-2023-44821 affect Gifsicle?
CVE-2023-44821 affects Gifsicle through version 1.94 by potentially allowing untrusted input to impact Gif_Realloc calls, leading to a denial of service due to memory consumption.
Is the impact of CVE-2023-44821 disputed?
Yes, the impact of CVE-2023-44821 has been disputed by multiple parties due to the argument that Gifsicle is not commonly used for unattended operation.
How can I fix CVE-2023-44821?
To fix CVE-2023-44821, it is recommended to update Gifsicle to a version beyond 1.94 or apply any official patches or fixes provided by the vendor.