CVE-2017-18120

HIGH

Lcdf Gifsicle - Double Free

Title source: rule

Description

A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different vulnerability than CVE-2017-1000421.

Scores

CVSS v3 7.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (1)

lcdf/gifsicle

Timeline

Published Feb 02, 2018
Tracked Since Feb 18, 2026