Name
giflib
Version
5.2.2
Type
library
Description
shared library for GIF images
Licenses
MIT
PURL
-
CPE
cpe:2.3:*:giflib_project:giflib:5.2.2:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Avoid potentuial double-free on weird images.
Eric S. Raymond <esr@thyrsus.com>
CVE-2026-23868
2
Makefile: fix typo in soname argument
Martin Jansa <martin.jansa@gmail.com>
3
Resolve SourceForge bug #187: CVE-2025-31344
"Eric S. Raymond" <esr@thyrsus.com>
CVE-2025-31344
Vulnerabilities#
Name
Analysis
Description
Exploitable
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
Patched
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
Patched
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C.
This issue affects giflib: through 5.2.2.
Exploitable
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.