CVE-2021-45972

The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:giftrans_project:giftrans:1.12.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-787 CWE-1284

10 Jan 2022, 21:31

Type Values Removed Values Added
References (MISC) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1002739 - (MISC) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1002739 - Exploit, Mailing List, Third Party Advisory
References (MISC) http://web.archive.org/web/20150801185019/ - (MISC) http://web.archive.org/web/20150801185019/ - Broken Link
References (MISC) https://www.abdn.ac.uk/tools/ibmpc/giftrans/index.hti - (MISC) https://www.abdn.ac.uk/tools/ibmpc/giftrans/index.hti - Broken Link
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:giftrans_project:giftrans:1.12.2:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 7.1

01 Jan 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-01 21:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-45972

Mitre link : CVE-2021-45972

CVE.ORG link : CVE-2021-45972


JSON object : View

Products Affected

debian

  • debian_linux

giftrans_project

  • giftrans
CWE
CWE-1284

Improper Validation of Specified Quantity in Input