LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

cairo: denial of service

Package(s):cairo CVE #(s):CVE-2006-0528
Created:March 21, 2006 Updated:March 31, 2006
Description: The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.
Alerts:
SuSE SUSE-SR:2006:007 2006-03-31
Ubuntu USN-265-1 2006-03-23
Mandriva MDKSA-2006:057 2006-03-20

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds