← Vulnerability feed

Vulnerability record · CVE-2018-11489 · published 26 May 2018

CVE-2018-11489: Giflib project giflib out-of-bounds write vulnerability

GGiflib Project · Giflib

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

8.8 CVSS 3.1 High EPSS 2.6% · top 15.5% CWE-129 · CWE-129CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12601Sam2p project sam2p out-of-bounds write vulnerabilityThere is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im…EPSS 2.1%9.8CVE-2018-12578Sam2p project sam2p out-of-bounds write vulnerabilityThere is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified …EPSS 2.1%9.8CVE-2018-7551Sam2p project sam2p use after free vulnerabilityThere is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial o…EPSS 2.2%9.8CVE-2018-7552Sam2p project sam2p memory buffer overflow vulnerabilityThere is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead t…EPSS 2.2%9.8CVE-2018-7553Sam2p project sam2p out-of-bounds write vulnerabilityThere is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service o…EPSS 2.5%9.8CVE-2018-7554Sam2p project sam2p use after free vulnerabilityThere is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of se…EPSS 2.2%9.8CVE-2017-14636Sam2p project sam2p integer overflow vulnerabilityBecause of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPa…EPSS 1.2%9.8CVE-2017-14637Sam2p project sam2p memory buffer overflow vulnerabilityIn sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal addre…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2018-11489), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.