CVE Vulnerabilities

CVE-2009-2295

Published: Jul 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.

Affected Software

NameVendorStart VersionEnd Version
CamlimagesJun_furuse*2.2 (including)
AdviUbuntudapper*
AdviUbuntuhardy*
AdviUbuntuintrepid*
AdviUbuntujaunty*
AdviUbuntukarmic*
AdviUbuntuupstream*
CamlimagesUbuntudapper*
CamlimagesUbuntuhardy*
CamlimagesUbuntuintrepid*
CamlimagesUbuntujaunty*
CamlimagesUbuntuupstream*

References