Lcdf maintains Gifsicle, a specialized GIF image processing utility whose narrow scope belies its prominence in image-handling pipelines across web services and media tools. Vulnerabilities affecting the product skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-management weakness classes including double frees, use-after-free conditions, out-of-bounds writes, and NULL-pointer dereferences that are characteristic of C-based image parsers handling untrusted input. Defenders should treat patches for this utility as moderately urgent given its embedded role in conversion and optimization workflows; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lcdf over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000421CRITICAL Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution | Jan 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-19752HIGH The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference. | Sep 7, 2021 | 7.5 | 25 | NO | NO |
CVE-2017-18120HIGH A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously | Feb 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2023-46009HIGH gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c. | Oct 18, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-36193HIGH Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c. | Jun 23, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-44821MEDIUM Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been dispu | Oct 9, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lcdf.
Media articles that mention a CVE ID that affects a product developed by Lcdf — matched by CVE ID, not by vendor name.