PT-2009-1554 · Enlightenment Foundation Libraries · Imlib2

Published

2009-02-06

·

Updated

2017-08-08

·

CVE-2008-6079

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions imlib2 versions prior to 1.4.2
Description The issue allows context-dependent attackers to have an unspecified impact via a crafted file, including ARGB, BMP, JPEG, LBM, PNM, TGA, or XPM files. This is related to several heap and stack-based buffer overflows, partly due to integer overflows.
Recommendations For versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted files until a patch is available. Avoid using the vulnerable functions related to the processing of ARGB, BMP, JPEG, LBM, PNM, TGA, or XPM files in imlib2 until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-6079
DSA-2029-1

Affected Products

Imlib2