← Vulnerability feed

Vulnerability record · CVE-2009-5018 · published 14 January 2011

CVE-2009-5018: Catb gif2png memory buffer overflow vulnerability

Catb · Gif2png

Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code via a long command-line argument, as demonstrated by a CGI program that launches gif2png.

6.8 CVSS 2.0 Medium EPSS 11% · top 4.3% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code via a long command-line argument, as demonstrated by a CGI program that launches gif2png.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550978 Patch
http://bugs.gentoo.org/show_bug.cgi?id=346501
http://cvs.fedoraproject.org/viewvc/rpms/gif2png/devel/gif2png-overflow.patch?root=extras&view=log Patch
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051229.html Patch
http://lists.grok.org.uk/pipermail/full-disclosure/2009-December/072009.html Patch
http://openwall.com/lists/oss-security/2010/11/21/1 Patch
http://openwall.com/lists/oss-security/2010/11/22/1 Patch
http://openwall.com/lists/oss-security/2010/11/22/12
http://openwall.com/lists/oss-security/2010/11/22/3
http://secunia.com/advisories/42796 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201101-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:009
http://www.securityfocus.com/bid/41801
http://www.vupen.com/english/advisories/2010/3036 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0023 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0107
https://bugzilla.redhat.com/show_bug.cgi?id=547515 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/64820
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550978 Patch
http://bugs.gentoo.org/show_bug.cgi?id=346501
http://cvs.fedoraproject.org/viewvc/rpms/gif2png/devel/gif2png-overflow.patch?root=extras&view=log Patch
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051229.html Patch
http://lists.grok.org.uk/pipermail/full-disclosure/2009-December/072009.html Patch
http://openwall.com/lists/oss-security/2010/11/21/1 Patch
http://openwall.com/lists/oss-security/2010/11/22/1 Patch
http://openwall.com/lists/oss-security/2010/11/22/12
http://openwall.com/lists/oss-security/2010/11/22/3
http://secunia.com/advisories/42796 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201101-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:009
http://www.securityfocus.com/bid/41801
http://www.vupen.com/english/advisories/2010/3036 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0023 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0107
https://bugzilla.redhat.com/show_bug.cgi?id=547515 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/64820

Track CVE-2009-5018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2010-4694Catb gif2png memory buffer overflow vulnerabilityBuffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to cause a denial of service (application crash) or…EPSS 2.0%5.0CVE-2010-4695Catb gif2png memory buffer overflow vulnerabilityA certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian…EPSS 2.4%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2009-5018), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.