The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libimlib2", "binary_version": "1.4.6-2ubuntu0.1" }, { "binary_name": "libimlib2-dbgsym", "binary_version": "1.4.6-2ubuntu0.1" }, { "binary_name": "libimlib2-dev", "binary_version": "1.4.6-2ubuntu0.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libimlib2", "binary_version": "1.4.7-1ubuntu0.1" }, { "binary_name": "libimlib2-dbgsym", "binary_version": "1.4.7-1ubuntu0.1" }, { "binary_name": "libimlib2-dev", "binary_version": "1.4.7-1ubuntu0.1" } ] }