A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gifsicle | Lcdf | 1.90 (including) | 1.90 (including) |
Gifsicle | Ubuntu | artful | * |
Gifsicle | Ubuntu | esm-apps/xenial | * |
Gifsicle | Ubuntu | trusty | * |
Gifsicle | Ubuntu | trusty/esm | * |
Gifsicle | Ubuntu | upstream | * |
Gifsicle | Ubuntu | xenial | * |