Latest YouTube Video

Monday, December 21, 2015

[FD] giflib: heap overflow in giffix (CVE-2015-7555)

About ===== giflib[1] is a library for working with GIF images. It also provides several command-line utilities. CVE-2015-7555 ============= A heap overflow may occur in the giffix utility included in giflib-5.1.1 when processing records of the type `IMAGE_DESC_RECORD_TYPE' due to the allocated size of `LineBuffer' equaling the value of the logical screen width, `GifFileIn->SWidth', while subsequently having `GifFileIn->Image.Width' bytes of data written to it. giflib-5.1.1/util/giffix.c #35..194: ,-

Source: Gmail -> IFTTT-> Blogger

No comments: