Closed TimChan2001 closed 1 year ago
I believe these issues are addressed in 76b1f021dd185ceff7b4a71a9f96a6026aca06af and 06d533628b1f3a75d06cbb29773dc6aaa2916fc3.
Thank you for reporting them!
Will there be a new release soon with these fixes? Thanks.
This is CVE-2023-46009: gifsicle: floating point exception vulnerability via resize_stream at src/xform.c
Again, a release with this fix would be very much appreciated. Thanks.
I've released 1.95 with this fix.
Thank you!
We found 2 FPE bugs in gifsicle-1.94. Initially, we thought #193 would be applicable. However, upon discovering that the same reproduction steps didn't work in gifsicle-1.93, we believe this issue might be different.
Reproduction
Build gifsicle-1.94 with ASAN, then run
We ran it on a 64-bit Ubuntu 18.04.
ASAN Report
1) The POC can be found here. POC1
2) The POC can be found here. POC2