PT-2009-4717 · Compface · Compface
Nico Golde
·
Published
2009-07-01
·
Updated
2009-09-02
·
CVE-2009-2286
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
compface versions 1.5.2 and earlier
Description
A buffer overflow issue allows user-assisted attackers to cause a denial of service, resulting in a crash, by providing a long declaration in a .xbm file. This issue is specific to certain distributions of compface that have applied a particular patch.
Recommendations
For compface versions 1.5.2 and earlier, consider avoiding the use of .xbm files with long declarations until a fix is available. As a temporary workaround, restrict the processing of .xbm files to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Compface