RunningCod…"/> RunningCod…"/> RunningCod…"/>
CVE-2018-11490 PUBLISHED

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

EPSS 0.22% · 45.1th percentile

Risk Scores

EPSS Score
0.22%
45.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgiflib0, 4.1.6-11, 5.1.1-0ubuntu1
Ubuntu:18.04:LTSgiflib0, 5.1.4-1, 5.1.4-2

Timeline

References

Open in Interactive Console →