PT-2009-4627 · Xcftools · Xcftools

Jörgen Grahn

·

Published

2009-06-23

·

Updated

2011-01-04

·

CVE-2009-2175

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xcftools version 1.0.4
Description The issue is related to a stack-based buffer overflow in the flattenIncrementally function, which can be triggered by crafted images that cause a conversion to a location outside the canvas boundaries. This can lead to a denial of service (crash) and potentially allow the execution of arbitrary code. The flattenIncrementally function is reachable through the xcf2pnm and xcf2png utilities.
Recommendations For xcftools version 1.0.4, consider avoiding the use of crafted images that may cause conversions outside the canvas boundaries until a patch is available. As a temporary workaround, restrict the use of the xcf2pnm and xcf2png utilities to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2175

Affected Products

Xcftools