LWN.net Logo

gif2png: denial of service

Package(s):gif2png CVE #(s):CVE-2010-4694
Created:January 17, 2011 Updated:March 16, 2012
Description: From the Mandriva advisory:

Buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to cause a denial of service (application crash) or have unspecified other impact via a GIF file that contains many images, leading to long extensions such as .p100 for PNG output files, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.

Alerts:
Mandriva MDVSA-2011:009 2011-01-14
Gentoo 201203-15 2012-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds