An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
| Software | From | Fixed in |
|---|---|---|
| gif2apng_project / gif2apng | 1.9 | 1.9.x |
| debian / debian_linux | 9.0 | 9.0.x |