In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade giflib | Dec 6, 2022 | Aug 17, 2019 |
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Huawei Euleros 2_0_sp2 | — | Upgrade giflib | Dec 4, 2019 | Aug 17, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade giflib | Apr 16, 2020 | Aug 17, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade giflib | Nov 19, 2019 | Aug 17, 2019 |
| Suse | — | Upgrade libgif7Upgrade giflib-progsUpgrade libgif7-32bitUpgrade giflib-develUpgrade giflib-devel-32bit | Aug 9, 2024 | Aug 17, 2019 |
| Ubuntu | — | Upgrade giflib-toolsUpgrade libgif7 | Aug 21, 2019 | Aug 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub