CVE-2010-4694

medium

Description

Buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to cause a denial of service (application crash) or have unspecified other impact via a GIF file that contains many images, leading to long extensions such as .p100 for PNG output files, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/64754

https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4659

https://bugzilla.redhat.com/show_bug.cgi?id=547515

http://www.vupen.com/english/advisories/2011/0107

http://www.vupen.com/english/advisories/2011/0023

http://www.vupen.com/english/advisories/2010/3036

http://www.securityfocus.com/bid/45815

http://www.mandriva.com/security/advisories?name=MDVSA-2011:009

http://security.gentoo.org/glsa/glsa-201203-15.xml

http://security.gentoo.org/glsa/glsa-201101-01.xml

http://secunia.com/advisories/42796

http://openwall.com/lists/oss-security/2010/11/22/3

http://openwall.com/lists/oss-security/2010/11/22/12

http://openwall.com/lists/oss-security/2010/11/22/1

http://openwall.com/lists/oss-security/2010/11/21/1

http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051229.html

http://cvs.fedoraproject.org/viewvc/rpms/gif2png/devel/gif2png-overflow.patch?root=extras&view=log

http://cvs.fedoraproject.org/viewvc/rpms/gif2png/devel/gif2png-overflow.patch?revision=HEAD&root=extras&view=markup

http://bugs.gentoo.org/show_bug.cgi?id=346501

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550978

Details

Source: Mitre, NVD

Published: 2011-01-14

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.02006