Heap-based buffer overflow in GIFLIB - CVE-2018-11490
Published: April 25, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the DGifDecompressLine function in dgif_lib.c in GIFLIB because a certain "Private->RunningCode - 2" array index is not checked. A remote attacker can trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
EMC Cloud Tiering Appliance
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
giflib-devel
giflib-debugsource
libgif6
giflib-progs-debuginfo
giflib-progs
libgif6-debuginfo
libgif6-debuginfo-32bit
libgif6-32bit
libgif7-32bit-debuginfo
libgif7-debuginfo
libgif7-32bit
giflib-devel-32bit
libgif7
How to mitigate CVE-2018-11490
giflib-debugsource - addressed in versions 5.0.5-13.3.1, 5.2.1-150000.4.8.1
libgif6 - update to 5.0.5-13.3.1
giflib-progs-debuginfo - addressed in versions 5.0.5-13.3.1, 5.2.1-150000.4.8.1
giflib-progs - addressed in versions 5.0.5-13.3.1, 5.2.1-150000.4.8.1
libgif6-debuginfo - update to 5.0.5-13.3.1
libgif6-debuginfo-32bit - update to 5.0.5-13.3.1
libgif6-32bit - update to 5.0.5-13.3.1
libgif7-32bit-debuginfo - update to 5.2.1-150000.4.8.1
libgif7-debuginfo - update to 5.2.1-150000.4.8.1
libgif7-32bit - update to 5.2.1-150000.4.8.1
giflib-devel-32bit - update to 5.2.1-150000.4.8.1
libgif7 - update to 5.2.1-150000.4.8.1
EMC Cloud Tiering Appliance - update to 13.2.0.2.24