Medium severity5.5NVD Advisory· Published Apr 13, 2016· Updated Jun 17, 2026
CVE-2015-7555
CVE-2015-7555
Description
Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*range: <=5.1.1
- (no CPE)range: 5.1.1
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
- osv-coords18 versionspkg:rpm/opensuse/giflib&distro=openSUSE%20Tumbleweedpkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1
< 5.1.4-1.12+ 17 more
- (no CPE)range: < 5.1.4-1.12
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 4.1.6-13.1
- (no CPE)range: < 5.0.5-7.1
- (no CPE)range: < 5.0.5-7.1
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/135034/giflib-5.1.1-Heap-Overflow.htmlnvdExploit
- seclists.org/fulldisclosure/2015/Dec/83nvdExploit
- lists.fedoraproject.org/pipermail/package-announce/2016-January/174876.htmlnvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvd
- www.securityfocus.com/archive/1/537171/100/0/threadednvd
- www.securityfocus.com/bid/81697nvd
- www.securitytracker.com/id/1035331nvd
- source.android.com/security/bulletin/2017-05-01nvd
News mentions
0No linked articles in our index yet.