Vulnerability record · CVE-2019-15133 · published 17 August 2019
CVE-2019-15133: Giflib project giflib divide by zero vulnerability
GGiflib Project · Giflib
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
Description
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008 | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00008.html | Mailing ListThird Party Advisory |
| https://usn.ubuntu.com/4107-1/ | Third Party Advisory |
| https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13008 | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00008.html | Mailing ListThird Party Advisory |
| https://usn.ubuntu.com/4107-1/ | Third Party Advisory |
Track CVE-2019-15133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.