CVE Vulnerabilities

CVE-2016-3177

Double Free

Published: Jan 23, 2017 | Modified: Jan 24, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
NEGLIGIBLE

Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Giflib Giflib_project 5.1.2 (including) 5.1.2 (including)
Giflib Ubuntu precise *
Giflib Ubuntu trusty *
Giflib Ubuntu upstream *
Giflib Ubuntu wily *

Potential Mitigations

References