Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 20.04 LTS USN-5969-1 Critical: gif2apng Denial Of Service

ubuntu
Calendar Grey March 23, 2023
Scroller Ubuntu
Numerous security flaws addressed in gif2apng for Ubuntu, improving system reliability and mitigating denial of service threats.
Several security issues were fixed in gif2apng.

Summary

Several security issues were fixed in gif2apng.

Software Description:

- gif2apng: tool for converting animated GIF images to APNG format

Details:

It was discovered that gif2apng contained multiple heap-base overflows. An

attacker could potentially exploit this to cause a denial of service (system

crash). (CVE-2021-45909, CVE-2021-45910, CVE-2021-45911)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  gif2apng                        1.9+srconly-3ubuntu0.1

Ubuntu 18.04 LTS:
  gif2apng                        1.9+srconly-2ubuntu0.1

Ubuntu 16.04 ESM:
  gif2apng                        1.7-3ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5969-1

CVE-2021-45909, CVE-2021-45910, CVE-2021-45911

Severity
critical
Lowest
Low
Medium
High
Critical

March 23, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.