A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade giflib | Mar 26, 2024 | Jun 14, 2022 |
| Amazon Linux Ami 2 | — | Upgrade giflibUpgrade giflib-debuginfoUpgrade giflib-develUpgrade giflib-utils | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade giflibNo solution exists | May 15, 2025 | Jun 14, 2022 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Huawei Euleros 2_0_sp9 | — | Upgrade giflibUpgrade giflib-help | Apr 9, 2024 | Jun 14, 2022 |
| Suse | — | Upgrade giflib-devel-32bitUpgrade giflib-develUpgrade libgif7-32bitUpgrade giflib-progsUpgrade libgif6-32bitUpgrade libgif6Upgrade libgif7 | Aug 9, 2024 | Jun 14, 2022 |
| Ubuntu | — | Upgrade giflib-toolsUpgrade giflib-tools (Ubuntu Pro) | Jul 1, 2024 | Jun 14, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub