CVE Feed

    Dashboard / CVE / CVE-2010-4695

    CVE-2010-4695

    A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pathname specified on the command line, which might allow remote attackers to create PNG files in unintended directories via a crafted command-line argument, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.

    Published:Oct 14, 2009
    Last Modified:Apr 11, 2025
    EPS:Jan 14, 2011
    EPSS Score:0.00538
    CVSS Score:5

    Affected Products

    Vendor
    Catb
    Product
    Gif2png
    Vendor
    Debian
    Product
    Linux
    Vendor
    Redhat
    Product
    Fedora

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High