CVE-2021-45909
published 2021-12-28CVE-2021-45909: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.87%
55.2th percentile
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gif2apng | < gif2apng 1.9+srconly-3+deb11u1 (bullseye) | gif2apng 1.9+srconly-3+deb11u1 (bullseye) |
| gif2apng_project | gif2apng | — | — |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-3+deb11u1 | 1.9+srconly-3+deb11u1 |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-2ubuntu0.1 | 1.9+srconly-2ubuntu0.1 |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-3ubuntu0.1 | 1.9+srconly-3ubuntu0.1 |
| gif2apng_project | gif2apng | >= 0 < 1.7-3ubuntu0.1~esm1 | 1.7-3ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gif2apng vulnerabilities
osv·2023-03-23·CVSS 7.8
CVE-2021-45909 [HIGH] gif2apng vulnerabilities
gif2apng vulnerabilities
It was discovered that gif2apng contained multiple heap-base overflows. An
attacker could potentially exploit this to cause a denial of service (system
crash). (CVE-2021-45909, CVE-2021-45910, CVE-2021-45911)
GHSA
GHSA-c9fh-qp5h-24w7: An issue was discovered in gif2apng 1
ghsa_unreviewed·2021-12-29
CVE-2021-45909 [HIGH] CWE-787 GHSA-c9fh-qp5h-24w7: An issue was discovered in gif2apng 1
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.
OSV
CVE-2021-45909: An issue was discovered in gif2apng 1
osv·2021-12-28·CVSS 7.8
CVE-2021-45909 [HIGH] CVE-2021-45909: An issue was discovered in gif2apng 1
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.
Ubuntu
gif2apng vulnerabilities
vendor_ubuntu·2023-03-23·CVSS 7.8
CVE-2021-45911 [HIGH] gif2apng vulnerabilities
Title: gif2apng vulnerabilities
Summary: Several security issues were fixed in gif2apng.
It was discovered that gif2apng contained multiple heap-base overflows. An
attacker could potentially exploit this to cause a denial of service (system
crash). (CVE-2021-45909, CVE-2021-45910, CVE-2021-45911)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-45909: gif2apng - An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow v...
vendor_debian·2021·CVSS 7.8
CVE-2021-45909 [HIGH] CVE-2021-45909: gif2apng - An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow v...
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.
Scope: local
bullseye: resolved (fixed in 1.9+srconly-3+deb11u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-28
Published