giflib: heap overflow in giffix (CVE-2015-7555)

Posted by Hans Jerry Illikainen on Dec 21

About
=====

giflib[1] is a library for working with GIF images. It also provides
several command-line utilities.

CVE-2015-7555
=============

A heap overflow may occur in the giffix utility included in giflib-5.1.1
when processing records of the type `IMAGE_DESC_RECORD_TYPE’ due to the
allocated size of `LineBuffer’ equaling the value of the logical screen
width, `GifFileIn->SWidth’, while subsequently having…

Leave a Reply