RSS   Vulnerabilities for 'Apng2gif'   RSS

2017-03-17
 
CVE-2017-6962

 

 
An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is related to the read_chunk function making an unchecked addition of 12.

 
 
CVE-2017-6961

 

 
An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is related to the read_chunk function using the pChunk->size value (within the PNG file) to determine the amount of memory to allocate.

 
 
CVE-2017-6960

 

 
An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.

 


Copyright 2017, cxsecurity.com