Buffer Overflow Vulnerability in MiniUPnP ngiflib Product
CVE-2018-10677

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
2 May 2018

What is CVE-2018-10677?

The DecodeGifImg function in ngiflib.c of MiniUPnP's ngiflib version 0.4 does not properly validate the dimensions of images, specifically width and height. This oversight can be exploited by remote attackers to initiate a denial of service attack via specially crafted GIF files, which could result in a heap-based buffer overflow and lead to application crashes or other undefined impacts.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.