PT-2009-5056 · None · Camlimages

Tielei Wang

·

Published

2009-08-04

·

Updated

2017-08-17

·

CVE-2009-2660

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CamlImages version 2.2
Description The issue is related to multiple integer overflows that might allow attackers to execute arbitrary code. This can be triggered by images with large width and height values, leading to a heap-based buffer overflow. The vulnerability is associated with crafted GIF files in gifread.c and crafted JPEG files in jpegread.c.
Recommendations For CamlImages version 2.2, update to a version that fixes the integer overflows to prevent potential code execution. As a temporary workaround, consider restricting the processing of images with large width and height values to minimize the risk of exploitation. Avoid using the gifread.c and jpegread.c functions with untrusted image files until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2660
DSA-1857-1
DSA-1912-1
DSA-1912-2

Affected Products

Camlimages