Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 29 Jan 2016 07:03:16 +0800 (CST)
From: xiaoqixue_1  <>
Subject: Re:Re: a bug in gif2rgb.c in giflib-5.1.2

It has been fixed now.

GifFile->SHeight and GifFile->SWidth both could result to zero memory allocation actually.
the patch as follows:

--- a/util/gif2rgb.c+++ b/util/gif2rgb.c@@ -378,8 +378,8 @@
-    if (GifFile->SHeight == 0) {-	fprintf(stderr, "Image of height 0\n");+    if (GifFile->SHeight == 0 || GifFile->SWidth == 0) {+	fprintf(stderr, "Image of width or height 0\n");

At 2016-01-27 13:40:08, wrote:
>Hash: SHA256
>> We find a memory allocation whose size could be zero in gif2rgb.c.
>> and It will result to several memory out of bound read and write. the bug in gif2rgb.c:386 :
>> 386 if ((ScreenBuffer = (GifRowType *) 
>> 387 malloc(GifFile->SHeight * sizeof(GifRowType))) == NULL) 
>> 388 GIF_EXIT("Failed to allocate memory required, aborted.");
>> Please see "" for more details.
>Can you provide more information about the relationship between
> and the above instance of
>GifFile->SHeight in the malloc call? The
>patch for adds a check for
>"GifFile->SWidth == 0" but does not add new validation of the
>GifFile->SHeight value.
>- -- 
>CVE assignment team, MITRE CVE Numbering Authority
>M/S M300
>202 Burlington Road, Bedford, MA 01730 USA
>[ PGP key available through ]
>Version: GnuPG v1

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.