CVE-2023-44821
published 2023-10-09CVE-2023-44821: Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption)…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.31%
23.6th percentile
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gifsicle | — | — |
| lcdf | gifsicle | <= 1.94 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-44821: gifsicle - Gifsicle through 1.94, if deployed in a way that allows untrusted input to affec...
vendor_debian·2023·CVSS 5.5
CVE-2023-44821 [MEDIUM] CVE-2023-44821: gifsicle - Gifsicle through 1.94, if deployed in a way that allows untrusted input to affec...
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-vqf3-8wjf-vm68: Buffer Overflow vulnerability in gifsicle v
ghsa_unreviewed·2023-10-09
CVE-2023-44821 [MEDIUM] CWE-401 GHSA-vqf3-8wjf-vm68: Buffer Overflow vulnerability in gifsicle v
Buffer Overflow vulnerability in gifsicle v.1.92 allows a remote attacker to cause a denial of service via the --crop parameter in the command line parameters.
OSV
CVE-2023-44821: Gifsicle through 1
osv·2023-10-09·CVSS 5.5
CVE-2023-44821 [MEDIUM] CVE-2023-44821: Gifsicle through 1
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
OSV
CVE-2023-44821: ** DISPUTED ** Gifsicle through 1
osv·2023-10-09·CVSS 5.5
CVE-2023-44821 [MEDIUM] CVE-2023-44821: ** DISPUTED ** Gifsicle through 1
** DISPUTED ** Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kohler/gifsicle/issues/195https://github.com/kohler/gifsicle/issues/65https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3I6Z7VAHUYX3Q4DULJ76NFD2CIFZJYH5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WLTXJS6AIKPGVOAJ7EYC4HL3NEG6CGF/https://github.com/kohler/gifsicle/issues/195https://github.com/kohler/gifsicle/issues/65https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3I6Z7VAHUYX3Q4DULJ76NFD2CIFZJYH5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WLTXJS6AIKPGVOAJ7EYC4HL3NEG6CGF/https://lists.fedoraproject.org/archives/list/[email protected]/message/3WLTXJS6AIKPGVOAJ7EYC4HL3NEG6CGF/
2023-10-09
Published