PT-2006-7549 · Xzgv+1 · Xzgv+1

Andrea Barisani

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2006-1060

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zgv versions before 5.8 xzgv versions before 0.8
Description The issue is related to multiple vulnerabilities in the zgv and xzgv packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a heap-based buffer overflow in zgv and xzgv might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space.
Recommendations For zgv versions before 5.8, update to version 5.8 or later to resolve the issue. For xzgv versions before 0.8, update to version 0.8 or later to resolve the issue. As a temporary workaround, consider avoiding the use of JPEG images with more than 3 output components, such as CMYK or YCCK color spaces, until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01808
BDU:2015-02407
CVE-2006-1060
DSA-1037-1
DSA-1038-1
OPENSUSE-SU-2024:10151-1

Produtos afetados

Xzgv
Zgv