Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gifsicle | Lcdf | * | 1.94 (including) |
Gifsicle | Ubuntu | bionic | * |
Gifsicle | Ubuntu | lunar | * |
Gifsicle | Ubuntu | mantic | * |
Gifsicle | Ubuntu | trusty | * |
Gifsicle | Ubuntu | xenial | * |