CVE-2021-45910
published 2021-12-28CVE-2021-45910: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.87%
55.3th percentile
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gif2apng | < gif2apng 1.9+srconly-3+deb11u1 (bullseye) | gif2apng 1.9+srconly-3+deb11u1 (bullseye) |
| gif2apng_project | gif2apng | — | — |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-3+deb11u1 | 1.9+srconly-3+deb11u1 |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-2ubuntu0.1 | 1.9+srconly-2ubuntu0.1 |
| gif2apng_project | gif2apng | >= 0 < 1.9+srconly-3ubuntu0.1 | 1.9+srconly-3ubuntu0.1 |
| gif2apng_project | gif2apng | >= 0 < 1.7-3ubuntu0.1~esm1 | 1.7-3ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gif2apng vulnerabilities
vendor_ubuntu·2023-03-23·CVSS 7.8
CVE-2021-45911 [HIGH] gif2apng vulnerabilities
Title: gif2apng vulnerabilities
Summary: Several security issues were fixed in gif2apng.
It was discovered that gif2apng contained multiple heap-base overflows. An
attacker could potentially exploit this to cause a denial of service (system
crash). (CVE-2021-45909, CVE-2021-45910, CVE-2021-45911)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-45910: gif2apng - An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow w...
vendor_debian·2021·CVSS 7.8
CVE-2021-45910 [HIGH] CVE-2021-45910: gif2apng - An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow w...
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
Scope: local
bullseye: resolved (fixed in 1.9+srconly-3+deb11u1)
OSV
gif2apng vulnerabilities
osv·2023-03-23·CVSS 7.8
CVE-2021-45909 [HIGH] gif2apng vulnerabilities
gif2apng vulnerabilities
It was discovered that gif2apng contained multiple heap-base overflows. An
attacker could potentially exploit this to cause a denial of service (system
crash). (CVE-2021-45909, CVE-2021-45910, CVE-2021-45911)
GHSA
GHSA-jfjg-288w-6ffp: An issue was discovered in gif2apng 1
ghsa_unreviewed·2021-12-29
CVE-2021-45910 [HIGH] CWE-787 GHSA-jfjg-288w-6ffp: An issue was discovered in gif2apng 1
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
OSV
CVE-2021-45910: An issue was discovered in gif2apng 1
osv·2021-12-28·CVSS 7.8
CVE-2021-45910 [HIGH] CVE-2021-45910: An issue was discovered in gif2apng 1
An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-28
Published