PT-2009-4717 · Compface · Compface

Nico Golde

·

Published

2009-07-01

·

Updated

2009-09-02

·

CVE-2009-2286

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions compface versions 1.5.2 and earlier
Description A buffer overflow issue allows user-assisted attackers to cause a denial of service, resulting in a crash, by providing a long declaration in a .xbm file. This issue is specific to certain distributions of compface that have applied a particular patch.
Recommendations For compface versions 1.5.2 and earlier, consider avoiding the use of .xbm files with long declarations until a fix is available. As a temporary workaround, restrict the processing of .xbm files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2286

Affected Products

Compface