{"id":"ECHO-b401-d90a-c280","summary":"There is a way to crash the gif2rgb cli tool with bad arguments, that has no fix, but:\n1. There is a warning in the man page https://man.archlinux.org/man/gif2rgb.1.en that bad input may core dump the tool,\n   so it's up to the user to sanitize the input\n2. It's in gif2rgb which is usually not installed.\n\nhttps://sourceforge.net/p/giflib/bugs/166/\nhttps://security-tracker.debian.org/tracker/CVE-2023-39742\n","modified":"2026-09-15T00:47:39.834962695Z","published":"2025-08-29T01:37:31.911598Z","withdrawn":"2025-10-28T12:41:16.010Z","upstream":["CVE-2023-39742"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2023-39742"}],"affected":[{"package":{"name":"giflib","ecosystem":"Echo","purl":"pkg:deb/echo/giflib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.2-1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-b401-d90a-c280.json"}}],"schema_version":"1.9.0"}