LWN.net Logo

file: heap-based buffer overflow

Package(s):file CVE #(s):CVE-2009-1515
Created:June 5, 2009 Updated:June 10, 2009
Description: From the Mandriva advisory: Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file.
Alerts:
Mandriva MDVSA-2009:129 2009-06-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds