7.8
CVSSv3

CVE-2017-18120

Published: 02/02/2018 Updated: 24/10/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote malicious user to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.

Vulnerable Product Search on Vulmon Subscribe to Product

lcdf gifsicle 1.90

Vendor Advisories

Debian Bug report logs - #878739 gifsicle: double-free bug when running gifdiff Package: gifsicle; Maintainer for gifsicle is Herbert Parentes Fortes Neto <hpfn@debianorg>; Source for gifsicle is src:gifsicle (PTS, buildd, popcon) Reported by: Joonun Jang <joonunjang@gmailcom> Date: Mon, 16 Oct 2017 11:15:04 UTC ...