PT-2010-5624 · Netpbm+1 · Netpbm+1

Jan Lieskovsky

+1

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2009-4274

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions netpbm versions prior to 10.47.07 netpbm versions prior to 10.49.00
Description The issue involves multiple vulnerabilities in the netpbm package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in converter/ppm/xpmtoppm.c, allowing context-dependent attackers to cause a denial of service or possibly execute arbitrary code via an XPM image file with a crafted header field associated with a large color index value.
Recommendations For netpbm versions prior to 10.47.07, update to version 10.47.07 or later to resolve the issue. For netpbm versions prior to 10.49.00, update to version 10.49.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the netpbm package until a patch is available.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-01175
BDU:2015-01176
BDU:2015-02006
BDU:2015-02007
BDU:2015-06434
BDU:2015-06437
BDU:2015-06440
BDU:2015-08581
BDU:2015-08582
BDU:2015-08583
BDU:2015-09684
CVE-2009-4274
DSA-2026-1
DTSA-206-1
RHSA-2011:1811
RHSA-2011_1811

Affected Products

Red Hat
Netpbm