6.5
CVE-2019-15133
- EPSS 1.54%
- Veröffentlicht 17.08.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:28:07
- Erkennungen
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Giflib Project ≫ Giflib Version < 5.1.7
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.54% | 0.717 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-369 Divide By Zero
The product divides a value by zero.
https://usn.ubuntu.com/4107-1/
https://lists.debian.org/debian-lts-announce/2022/12/msg00008.html
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008