Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T20:07:33.425Z

Reserved: 2023-10-02T00:00:00

Link: CVE-2023-44821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-10-09T20:15:10.583

Modified: 2024-11-21T08:26:03.653

Link: CVE-2023-44821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.