{"id":"CVE-2026-4985","summary":"dloebl CGIF GIF Image cgif.c cgif_addframe integer overflow","details":"A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to integer overflow. The attack may be initiated remotely. The identifier of the patch is b0ba830093f4317a5d1f345715d2fa3cd2dab474. It is suggested to install a patch to address this issue.","modified":"2026-07-22T00:06:03.952828Z","published":"2026-03-27T21:27:13.537Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-189","CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4985.json"},"references":[{"type":"WEB","url":"https://github.com/dloebl/cgif/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4985.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4985"},{"type":"ADVISORY","url":"https://vuldb.com/?id.353874"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.778278"},{"type":"REPORT","url":"https://github.com/dloebl/cgif/issues/110"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.353874"},{"type":"FIX","url":"https://github.com/dloebl/cgif/commit/b0ba830093f4317a5d1f345715d2fa3cd2dab474"},{"type":"FIX","url":"https://github.com/dloebl/cgif/pull/112"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dloebl/cgif","events":[{"introduced":"2bcdaea1b134ff31acc893d2e5920e68c411d59b"},{"fixed":"b0ba830093f4317a5d1f345715d2fa3cd2dab474"}],"database_specific":{"extracted_events":[{"introduced":"0.5.0"},{"last_affected":"0.5.0"},{"introduced":"0.5.1"},{"last_affected":"0.5.1"},{"introduced":"0.5.2"},{"last_affected":"0.5.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.5.0","0.5.1","0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4985.json","vanir_signatures_modified":"2026-07-22T00:06:03Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/dloebl/cgif/commit/b0ba830093f4317a5d1f345715d2fa3cd2dab474","target":{"file":"src/cgif.c","function":"cgif_addframe"},"deprecated":false,"digest":{"length":4580,"function_hash":"171136162460654712530482796871274633684"},"id":"CVE-2026-4985-49fe09fd","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dloebl/cgif/commit/b0ba830093f4317a5d1f345715d2fa3cd2dab474","target":{"file":"src/cgif.c"},"deprecated":false,"digest":{"line_hashes":["293867913414432174182311165443469586343","289721324328928541606126064462049485723","123221099516073638407936784006887341960","49113752948957356098600071949005746748","83292489927360328428365874813479561789","150802629640767370093492052631067446003","260213355676941278433434035868227134340","300149700293374886389481179831341764839"],"threshold":0.9},"id":"CVE-2026-4985-6792d045"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}