Debian Gifsicle vulnerabilities

6 known vulnerabilities affecting debian/gifsicle.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW5

Vulnerabilities

Page 1 of 1
CVE-2023-44821LOWCVSS 5.52023
CVE-2023-44821 [MEDIUM] CVE-2023-44821: gifsicle - Gifsicle through 1.94, if deployed in a way that allows untrusted input to affec... Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality t
debian
CVE-2023-46009LOWCVSS 7.82023
CVE-2023-46009 [HIGH] CVE-2023-46009: gifsicle - gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability v... gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-36193LOWCVSS 7.8fixed in gifsicle 1.94-1 (forky)2023
CVE-2023-36193 [HIGH] CVE-2023-36193: gifsicle - Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambigui... Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.94-1) sid: resolved (fixed in 1.94-1) trixie: resolved (fixed in 1.94-1)
debian
CVE-2020-19752LOWCVSS 7.5fixed in gifsicle 1.93-2 (bookworm)2020
CVE-2020-19752 [HIGH] CVE-2020-19752: gifsicle - The find_color_or_error function in gifsicle 1.92 contains a NULL pointer derefe... The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 1.93-2) bullseye: open forky: resolved (fixed in 1.93-2) sid: resolved (fixed in 1.93-2) trixie: resolved (fixed in 1.93-2)
debian
CVE-2017-1000421CRITICALCVSS 9.8fixed in gifsicle 1.90-1 (bookworm)2017
CVE-2017-1000421 [CRITICAL] CVE-2017-1000421: gifsicle - Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gi... Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution Scope: local bookworm: resolved (fixed in 1.90-1) bullseye: resolved (fixed in 1.90-1) forky: resolved (fixed in 1.90-1) sid: resolved (fixed in 1.90-1) trixie: resolved (fixed in 1.90-1)
debian
CVE-2017-18120LOWCVSS 9.8fixed in gifsicle 1.91-1 (bookworm)2017
CVE-2017-18120 [CRITICAL] CVE-2017-18120: gifsicle - A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows ... A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421. Scope: local bookworm: resolved (fixed in 1.91-1) bullseye: resolved (fixed in 1.91-1)
debian