[CVE patch] CVE-2016-3977 in giflib version 5.1.2 92/88692/1 accepted/tizen_3.0.m2_mobile accepted/tizen_3.0.m2_tv accepted/tizen_3.0.m2_wearable accepted/tizen_3.0_common accepted/tizen_3.0_ivi accepted/tizen_3.0_mobile accepted/tizen_3.0_tv accepted/tizen_3.0_wearable accepted/tizen_common accepted/tizen_ivi accepted/tizen_mobile accepted/tizen_tv accepted/tizen_wearable tizen_3.0.m2 tizen_3.0_tv accepted/tizen/3.0.m2/mobile/20170104.142955 accepted/tizen/3.0.m2/tv/20170104.143444 accepted/tizen/3.0.m2/wearable/20170104.143842 accepted/tizen/3.0/common/20161114.110602 accepted/tizen/3.0/ivi/20161011.044149 accepted/tizen/3.0/mobile/20161015.033231 accepted/tizen/3.0/tv/20161016.004724 accepted/tizen/3.0/wearable/20161015.082844 accepted/tizen/common/20160921.162249 accepted/tizen/ivi/20160922.042639 accepted/tizen/mobile/20160922.042418 accepted/tizen/tv/20160922.042511 accepted/tizen/unified/20170309.035623 accepted/tizen/wearable/20160922.042556 submit/tizen/20160921.041639 submit/tizen_3.0.m2/20170104.093752 submit/tizen_3.0_common/20161104.104000 submit/tizen_3.0_ivi/20161010.000002 submit/tizen_3.0_mobile/20161015.000002 submit/tizen_3.0_tv/20161015.000002 submit/tizen_3.0_wearable/20161015.000002 submit/tizen_unified/20170308.100412
authorJiyong Min <jiyong.min@samsung.com>
Tue, 20 Sep 2016 08:37:27 +0000 (17:37 +0900)
committerJiyong Min <jiyong.min@samsung.com>
Tue, 20 Sep 2016 08:39:47 +0000 (17:39 +0900)
commit8236083c901e4740d31e916bccfecf37522f82f2
tree83fe5ac4eadedb74a9603271e7d1c7e3cadc32ac
parent1491cb513376d428780c3dcfa03383f532e06d8a
[CVE patch] CVE-2016-3977 in giflib version 5.1.2

 - Fix SF bug #87 Heap buffer overflow in 5.1.2 (gif2rgb).
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

Change-Id: I8fcf54bb71c5fb55e79a4c4150d348098984977b
Signed-off-by: Jiyong Min <jiyong.min@samsung.com>
NEWS
lib/dgif_lib.c
util/gif2rgb.c