CVE-2017-18120
published 2018-02-02CVE-2017-18120: A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other…
PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.76%
75.5th percentile
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gifsicle | < gifsicle 1.91-1 (bookworm) | gifsicle 1.91-1 (bookworm) |
| lcdf | gifsicle | — | — |
| lcdf | gifsicle | >= 0 < 1.91-1 | 1.91-1 |
| lcdf | gifsicle | >= 0 < 1.91-1 | 1.91-1 |
| lcdf | gifsicle | >= 0 < 1.91-1 | 1.91-1 |
| lcdf | gifsicle | >= 0 < 1.91-1 | 1.91-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6f9j-p2gf-3f72: A double-free bug in the read_gif function in gifread
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2017-18120 [CRITICAL] CWE-415 GHSA-6f9j-p2gf-3f72: A double-free bug in the read_gif function in gifread
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
OSV
CVE-2017-18120: A double-free bug in the read_gif function in gifread
osv·2018-02-02·CVSS 9.8
CVE-2017-18120 [CRITICAL] CVE-2017-18120: A double-free bug in the read_gif function in gifread
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
Ubuntu
Gifsicle vulnerabilities
vendor_ubuntu·2021-03-15
CVE-2017-18120 Gifsicle vulnerabilities
Title: Gifsicle vulnerabilities
Summary: Gifsicle could be made to crash or run programs as an administrator
if it opened a specially crafted file.
It was discovered that Gifsicle did not properly handle certain input. If a
user were tricked into opening a malicious GIF, an attacker could
potentially execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-18120: gifsicle - A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows ...
vendor_debian·2017·CVSS 9.8
CVE-2017-18120 [CRITICAL] CVE-2017-18120: gifsicle - A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows ...
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
Scope: local
bookworm: resolved (fixed in 1.91-1)
bullseye: resolved (fixed in 1.91-1)
forky: resolved (fixed in 1.91-1)
sid: resolved (fixed in 1.91-1)
trixie: resolved (fixed in 1.91-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18120 gifsicle: Double-free in the read_gif function [epel-all]
bugzilla·2018-02-05·CVSS 7.8
CVE-2017-18120 [HIGH] CVE-2017-18120 gifsicle: Double-free in the read_gif function [epel-all]
CVE-2017-18120 gifsicle: Double-free in the read_gif function [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2017-18120 gifsicle: Double-free in the read_gif function
bugzilla·2018-02-05·CVSS 9.8
CVE-2017-18120 [CRITICAL] CVE-2017-18120 gifsicle: Double-free in the read_gif function
CVE-2017-18120 gifsicle: Double-free in the read_gif function
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
Upstream issue:
https://github.com/kohler/gifsicle/issues/117
Upstream patch:
https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f909
Discussion:
Created gifsicle tracking bugs for this issue:
Affects: epel-all [bug 1542036]
Affects: fedora-all [bug 1542037]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to
Bugzilla
CVE-2017-18120 gifsicle: Double-free in the read_gif function [fedora-all]
bugzilla·2018-02-05·CVSS 7.8
CVE-2017-18120 [HIGH] CVE-2017-18120 gifsicle: Double-free in the read_gif function [fedora-all]
CVE-2017-18120 gifsicle: Double-free in the read_gif function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f909https://github.com/kohler/gifsicle/issues/117https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f909https://github.com/kohler/gifsicle/issues/117
2018-02-02
Published