CVE Vulnerabilities

CVE-2009-2295

Published: Jul 05, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.

Affected Software

Name Vendor Start Version End Version
Camlimages Jun_furuse * 2.2 (including)
Advi Ubuntu dapper *
Advi Ubuntu hardy *
Advi Ubuntu intrepid *
Advi Ubuntu jaunty *
Advi Ubuntu karmic *
Advi Ubuntu upstream *
Camlimages Ubuntu dapper *
Camlimages Ubuntu hardy *
Camlimages Ubuntu intrepid *
Camlimages Ubuntu jaunty *
Camlimages Ubuntu upstream *

References