|
|
| |
|
| |
xcftools: code execution
| Package(s): | gnome-xcf-thumbnailer |
CVE #(s): | CVE-2009-2175
|
| Created: | November 9, 2010 |
Updated: | November 10, 2010 |
| Description: |
From the CVE entry:
Stack-based buffer overflow in the flattenIncrementally function in flatten.c
in xcftools 1.0.4, as reachable from the (1) xcf2pnm and (2) xcf2png utilities,
allows remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code via a crafted image that causes a conversion to a
location "above or to the left of the canvas." NOTE: some of these details are
obtained from third party information.
|
| Alerts: |
|
( Log in to post comments)
|
|
|