PT-2016-3184 · Enlightenment Foundation+2 · Imlib2+2

Yuriy M. Kaminskiy

·

Published

2016-04-06

·

Updated

2024-11-26

·

CVE-2016-4024

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions imlib2 versions prior to 1.4.9
Description The issue is caused by an integer overflow in the imlib2 graphic library on 32-bit platforms, which can lead to an out-of-bounds heap memory write operation. This can be exploited by a remote attacker using a specially crafted large image to execute arbitrary code.
Recommendations For versions prior to 1.4.9, update to version 1.4.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of large images to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1274
BDU:2017-02328
CVE-2016-4024
DSA-3555-1
MGASA-2016-0144
ROSA-SA-2024-2533
USN-3075-1

Affected Products

Alt Linux
Ubuntu
Imlib2