CVE-2019-17534

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
13/10/2019
Last modified:
29/09/2023

Description

vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:* 8.8.2 (excluding)