Release date:
Updated on: 2012-03-19
Affected Systems:
Gif2png Gif2png 2.5.2
Gif2png Gif2png 2.5.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45920
CVE (CAN) ID: CVE-2010-4695
Gif2pngis a command line program specially used to convert .gif to .png image format.
A security vulnerability exists in the implementation of gif2png, which allows remote attackers to create PNG files in illegal directories, resulting in access denial or memory corruption.
<* Source: Vincent Danen
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 547515
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Gif2png
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://catb.org/esr/gif2png/