Executive Summary
| Summary | |
|---|---|
| Title | gif2png: User-assisted execution of arbitrary code |
| Informations | |||
|---|---|---|---|
| Name | GLSA-201101-01 | First vendor Publication | 2011-01-05 |
| Vendor | Gentoo | Last vendor Modification | 2011-01-05 |
| Severity (Vendor) | Normal | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 6.8 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Synopsis gif2png contains a stack overflow vulnerability when parsing command line arguments. Background gif2png is a command line program that converts image files from the Graphics Interchange Format (GIF) format to the Portable Network Graphics (PNG) format. Description gif2png contains a command line parsing vulnerability that may result in a stack overflow due to an unexpectedly long input filename. Impact A remote attacker could entice a user to open a specially crafted image, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service. Note that applications relying on gif2png to process images can also trigger the vulnerability. Workaround There is no known workaround at this time. Resolution All gif2png users should upgrade to the latest stable version: # emerge --sync # emerge --ask --oneshot --verbose ">=media-gfx/gif2png-2.5.1-r1" References [ 1 ] CVE-2009-5018 : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5018 Availability This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201101-01.xml |
Original Source
| Url : http://security.gentoo.org/glsa/glsa-201101-01.xml |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 70480 | gif2png gif2png.c Multiple Image GIF File Handling Overflow DoS |
| 63300 | gif2png gif2png.c Command Line Argument Overflow |

GLSA-201101-01
(Medium)





