Medium severity6.5NVD Advisory· Published Aug 17, 2019· Updated Jun 17, 2026
CVE-2019-15133
CVE-2019-15133
Description
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
Affected products
19cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*range: <5.1.7
- (no CPE)range: <2019-02-16
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- GIFLIB/GIFLIBdescription
- osv-coords12 versionspkg:rpm/opensuse/giflib&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/giflib&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/giflib&distro=openSUSE%20Tumbleweedpkg:rpm/suse/giflib&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/giflib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2
< 5.2.1-150000.4.8.1+ 11 more
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.2-1.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
- (no CPE)range: < 5.2.1-150000.4.8.1
Patches
Vulnerability mechanics
References
3- bugs.chromium.org/p/oss-fuzz/issues/detailnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00008.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/4107-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.