CVE-2005-3350Libungif vulnerability

9 documents7 sources
Severity
7.5HIGHNVD
EPSS
5.0%
top 10.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 1

Description

libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/giflib< giflib 4.1.4-1 (bookworm)
Debiangiflib_project/giflib< 4.1.4-1+3

🔴Vulnerability Details

2
GHSA
GHSA-mh2j-cpx3-ww24: libungif library before 42022-05-01
OSV
CVE-2005-3350: libungif library before 42005-11-04

📋Vendor Advisories

3
Ubuntu
libungif vulnerabilities2005-11-07
Red Hat
giflib/libunfig: memory corruption via a crafted GIF2005-11-03
Debian
CVE-2005-3350: giflib - libungif library before 4.1.0 allows attackers to corrupt memory and possibly ex...2005

💬Community

3
Bugzilla
CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF2009-04-08
Bugzilla
CVE-2005-2974 Several libungif issues (CVE-2005-3350)2005-10-21
Bugzilla
CVE-2005-2974 Several libungif issues (CVE-2005-3350)2005-10-21