Out-of-Bounds Affecting gif2png package, versions <2.5.4-2


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.97% (84th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN9-GIF2PNG-294803
  • published14 Jan 2011
  • disclosed14 Jan 2011

Introduced: 14 Jan 2011

CVE-2010-4695  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade Debian:9 gif2png to version 2.5.4-2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gif2png package and not the gif2png package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pathname specified on the command line, which might allow remote attackers to create PNG files in unintended directories via a crafted command-line argument, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.

CVSS Scores

version 3.1