Rapid7 Vulnerability & Exploit Database

RHSA-2009:0444: giflib security update

Back to Search

RHSA-2009:0444: giflib security update

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
11/03/2005
Created
07/25/2018
Added
09/12/2009
Modified
07/04/2017

Description

The giflib packages contain a shared library of functions for loading andsaving GIF image files. This library is API and ABI compatible withlibungif, the library that supported uncompressed GIF image files while theUnisys LZW patent was in effect.Several flaws were discovered in the way giflib decodes GIF images. Anattacker could create a carefully crafted GIF image that could cause anapplication using giflib to crash or, possibly, execute arbitrary code whenopened by a victim. (CVE-2005-2974, CVE-2005-3350)All users of giflib are advised to upgrade to these updated packages, whichcontain backported patches to resolve these issues. All runningapplications using giflib must be restarted for the update to take effect.

Solution(s)

  • redhat-upgrade-giflib
  • redhat-upgrade-giflib-devel
  • redhat-upgrade-giflib-utils

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;