PT-2009-4627 · Xcftools · Xcftools

Jörgen Grahn

·

Publicado

2009-06-23

·

Atualizado

2011-01-04

·

CVE-2009-2175

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xcftools version 1.0.4
Description The issue is related to a stack-based buffer overflow in the flattenIncrementally function, which can be triggered by crafted images that cause a conversion to a location outside the canvas boundaries. This can lead to a denial of service (crash) and potentially allow the execution of arbitrary code. The flattenIncrementally function is reachable through the xcf2pnm and xcf2png utilities.
Recommendations For xcftools version 1.0.4, consider avoiding the use of crafted images that may cause conversions outside the canvas boundaries until a patch is available. As a temporary workaround, restrict the use of the xcf2pnm and xcf2png utilities to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2175

Produtos afetados

Xcftools