cbcvebase.
CVE-2021-45909
published 2021-12-28

CVE-2021-45909: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large…

PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.87%
55.2th percentile
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiangif2apng< gif2apng 1.9+srconly-3+deb11u1 (bullseye)gif2apng 1.9+srconly-3+deb11u1 (bullseye)
gif2apng_projectgif2apng
gif2apng_projectgif2apng>= 0 < 1.9+srconly-3+deb11u11.9+srconly-3+deb11u1
gif2apng_projectgif2apng>= 0 < 1.9+srconly-2ubuntu0.11.9+srconly-2ubuntu0.1
gif2apng_projectgif2apng>= 0 < 1.9+srconly-3ubuntu0.11.9+srconly-3ubuntu0.1
gif2apng_projectgif2apng>= 0 < 1.7-3ubuntu0.1~esm11.7-3ubuntu0.1~esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.