Bug 2452517 (CVE-2026-4985) - CVE-2026-4985 cgif: dloebl CGIF: Denial of Service via integer overflow in GIF image handling
Summary: CVE-2026-4985 cgif: dloebl CGIF: Denial of Service via integer overflow in GI...
Keywords:
Status: NEW
Alias: CVE-2026-4985
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2452785
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-27 22:02 UTC by OSIDB Bzimport
Modified: 2026-03-29 07:30 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-27 22:02:50 UTC
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to integer overflow. The attack may be initiated remotely. The identifier of the patch is b0ba830093f4317a5d1f345715d2fa3cd2dab474. It is suggested to install a patch to address this issue. VulDB is the best source for vulnerability data and more expert information about this specific topic.


Note You need to log in before you can comment on or make changes to this bug.