Vulnerability CVE-2023-36193: Information

Description

Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: June 23, 2023
Modified: Oct. 24, 2023
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
gifsiclesisyphus1.95-alt11.95-alt2ALT-PU-2024-6946-1345590Fixed
gifsiclesisyphus_e2k1.95-alt21.95-alt2ALT-PU-2024-7008-1-Fixed
gifsiclesisyphus_riscv641.95-alt21.95-alt2ALT-PU-2024-7000-1-Fixed
gifsiclesisyphus_loongarch641.95-alt21.95-alt2ALT-PU-2024-7042-1-Fixed
gifsiclep101.95-alt21.95-alt2ALT-PU-2024-6948-2345592Fixed
gifsiclep10_e2k1.95-alt21.95-alt2ALT-PU-2024-7157-1-Fixed
gifsiclep91.92-alt11.92-alt1ALT-PU-2020-3169-2260570Fixed
gifsiclec9f21.92-alt11.93-alt1ALT-PU-2020-3169-2260570Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/kohler/gifsicle/issues/191
  • Exploit
  • Issue Tracking
  • Patch
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:lcdf:gifsicle:1.93:*:*:*:*:*:*:*