Catb maintains a focused image-conversion utility, gif2png, that handles binary file parsing and transformation. The observed vulnerability signal centers on improper memory-buffer boundary restrictions, a characteristic risk in format-conversion tools that must parse and reconstruct untrusted input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Catb over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-5018MEDIUM Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code via a long command-line argument, as demonst | Jan 14, 2011 | 6.8 | 36 | NO | YES |
CVE-2010-4694MEDIUM Buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to cause a denial of service (application crash) or have unspecified other impact | Jan 14, 2011 | 6.8 | 22 | NO | NO |
CVE-2010-4695MEDIUM A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pat | Jan 14, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Catb.
Media articles that mention a CVE ID that affects a product developed by Catb — matched by CVE ID, not by vendor name.