CVE-2005-2974NULL Pointer Dereference in Libungif

Severity
2.6LOWNVD
EPSS
4.9%
top 10.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 1

Description

libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.

CVSS vector

AV:N/AC:H/C:N/I:N/A:PExploitability: 4.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/giflib< giflib 4.1.4-1 (bookworm)
Debiangiflib_project/giflib< 4.1.4-1+3

🔴Vulnerability Details

2
GHSA
GHSA-mj64-44v8-gvpx: libungif library before 42022-05-01
OSV
CVE-2005-2974: libungif library before 42005-11-04

📋Vendor Advisories

3
Ubuntu
libungif vulnerabilities2005-11-07
Red Hat
giflib/libunfig: NULL pointer dereference crash2005-11-03
Debian
CVE-2005-2974: giflib - libungif library before 4.1.0 allows attackers to cause a denial of service via ...2005

💬Community

4
Bugzilla
CVE-2005-2974 giflib/libunfig: NULL pointer dereference crash2009-04-08
Bugzilla
CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF2009-04-08
Bugzilla
CVE-2005-2974 Several libungif issues (CVE-2005-3350)2005-10-21
Bugzilla
CVE-2005-2974 Several libungif issues (CVE-2005-3350)2005-10-21