CVE-2018-10717: Miniupnp Project Ngiflib

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file, a different vulnerability than CVE-2018-10677.

Affected products

Published 2018-05-03. Last modified 2026-06-17.