PT-2010-3188 · Ziproxy · Ziproxy

Published

2010-05-26

·

Updated

2018-10-10

·

CVE-2010-1513

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ziproxy versions prior to 3.0.1
Description The issue is related to multiple integer overflows in the src/image.c file, which can be exploited by remote attackers to execute arbitrary code. This can be achieved through a large JPG image related to the jpg2bitmap function or a large PNG image related to the png2bitmap function, leading to heap-based buffer overflows.
Recommendations For versions prior to 3.0.1, update to version 3.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of large JPG and PNG images to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1513

Affected Products

Ziproxy