A global buffer overflow in OptiPNG 0.7.6 allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an uncontrolled loop in the LZWReadByte function of the gifread.c file.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade optipng | Dec 10, 2017 | Nov 24, 2017 |
| Gentoo Linux | — | Upgrade media-gfx/optipng. | Jan 8, 2018 | Nov 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 24, 2017 |
| Suse | — | Upgrade optipngUpgrade optipng-debuginfoUpgrade optipng-debugsource | Dec 2, 2017 | Nov 24, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub