UBUNTU-CVE-2017-18120
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-18120
UBUNTU-CVE-2017-18120
Summary:
Details: A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
References: https://ubuntu.com/security/CVE-2017-18120, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878739, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881120, https://github.com/kohler/gifsicle/commit/118a46090c50829dc543179019e6140e1235f909, https://github.com/kohler/gifsicle/commit/263cd4519f45bc6ecde74ee280eb1d68ee2de642, https://github.com/kohler/gifsicle/issues/117, https://www.cve.org/CVERecord?id=CVE-2017-18120, https://ubuntu.com/security/notices/USN-4803-1
Affected packages
Package
Name: gifsicle
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
