8.8
CVSSv3

CVE-2018-11490

Published: 26/05/2018 Updated: 03/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that GIFLIB incorrectly handled certain GIF files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2016-3977)

Vulnerable Product Search on Vulmon Subscribe to Product

sam2p project sam2p 0.49.4

giflib project giflib

debian debian linux 10.0

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 16.04

Vendor Advisories

Debian Bug report logs - #904114 CVE-2018-11490 Package: src:giflib; Maintainer for src:giflib is Debian QA Group <packages@qadebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 19 Jul 2018 21:39:04 UTC Severity: important Tags: security, upstream Found in version giflib/514-01 Fixed in vers ...
Several security issues were fixed in GIFLIB ...
The DGifDecompressLine function in dgif_libc in GIFLIB (possibly version 30x), as later shipped in cgifc in sam2p 0494, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked This will lead to a denial of service or possibly unspecified other impact ...