CVE-2023-44821

Source
https://cve.org/CVERecord?id=CVE-2023-44821
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-44821.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-44821
Downstream
Published
2023-10-09T00:00:00Z
Modified
2026-08-12T03:51:22.709495086Z
Summary
[none]
Details

Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not commonly used for unattended operation in which new input arrives for a long-running process, does not ship with functionality to link it into another application as a library, and does not have realistic use cases in which an adversary controls the entire command line.

Database specific
{
    "isDisputed": true,
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/44xxx/CVE-2023-44821.json"
}
References

Affected packages

Git / github.com/kohler/gifsicle

Affected ranges

Type
GIT
Repo
https://github.com/kohler/gifsicle
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.94"
        },
        {
            "last_affected": "1.94"
        }
    ],
    "cpe": "cpe:2.3:a:lcdf:gifsicle:*:*:*:*:*:*:*:*"
}

Affected versions

v1.*
v1.10
v1.10b1
v1.11
v1.11.1
v1.14.1
v1.15b
v1.18
v1.19
v1.21
v1.22
v1.24
v1.25
v1.26
v1.30
v1.35
v1.37
v1.38
v1.39
v1.40
v1.42
v1.43
v1.44
v1.45
v1.46
v1.47
v1.48
v1.50
v1.51
v1.52
v1.53
v1.54
v1.55
v1.56
v1.57
v1.58
v1.59
v1.60
v1.61
v1.62
v1.63
v1.64
v1.65
v1.66
v1.67
v1.68
v1.69
v1.70
v1.71
v1.72
v1.73
v1.74
v1.75
v1.76
v1.77
v1.78
v1.79
v1.80
v1.81
v1.82
v1.84
v1.85
v1.86
v1.87
v1.88
v1.89
v1.90
v1.91
v1.92
v1.93

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-44821.json"