Release date:
2026-08-25 08:36:48 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in gif2rgb
- debian/patches/CVE-2020-23922.patch: bound each pixel index against
the active color table before indexing ColorMap->Colors in
DumpScreen2RGB in util/gif2rgb.c.
- CVE-2020-23922
* SECURITY UPDATE: memory leak leading to denial of service
- debian/patches/CVE-2021-40633.patch: free every ScreenBuffer row, not
just the row-pointer array, at the end of GIF2RGB in
util/gif2rgb.c.
- CVE-2021-40633
* SECURITY UPDATE: double free in GifMakeSavedImage
- debian/patches/CVE-2026-23868.patch: null out the heap pointers
aliased by the shallow copy of CopyFrom, test the source record when
deciding what to deep-copy, and restore ExtensionBlockCount after the
extension blocks are copied, in lib/gifalloc.c.
- CVE-2026-23868
Updated packages:
-
giflib-tools_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:9cca7b0244b450b4cc338ed8591466ba0acfde53
-
libgif-dev_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:2c33b893c22c359fd8c7ec70497c55908d32614c
-
libgif7_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:83e03f7315f9ae228e5ac431eb38eeab56a92172
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.