CVE-2024-45993

Published: 09/30/2024 17:15:04
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
MEDIUM
CVSS v3: 6.5

Status

DocFilters Release Package State Justification Comment
0.0.0.1 giflib (5.2.1) Not Affected Code Not Present not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue
25.3 giflib (5.2.1) Not Affected Code Not Present not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue
25.2 giflib (5.2.1) Not Affected Code Not Present not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue
25.1.1 giflib (5.2.1) Not Affected Code Not Present not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue
25.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.4 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.4.0 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.3 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.2.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.2 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
24.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
23.3 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
23.2.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
23.2 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
23.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
22.4 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
22.3 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
22.2 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
22.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.11.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.11 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.8.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.8 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.5.1 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.5.0 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
21.2.0 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.20 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.19.3667 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.18.3599 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.17 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.16.3445 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.15.3368 giflib (5.2.1) Not Affected Code Not Present 5.2.1 does not match CVE configuration.
11.4.14.3263 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.13.3179 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.12.3054 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.11.3040 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.11.2990 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.10.2934 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.9.2878 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.
11.4.8.2822 giflib (5.1.4) Not Affected Code Not Present 5.1.4 does not match CVE configuration.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
LOW
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
LOW
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Version
3.1

References