LWN.net Logo

xcftools: code execution

Package(s):gnome-xcf-thumbnailer CVE #(s):CVE-2009-2175
Created:November 9, 2010 Updated:November 10, 2010
Description: From the CVE entry:

Stack-based buffer overflow in the flattenIncrementally function in flatten.c in xcftools 1.0.4, as reachable from the (1) xcf2pnm and (2) xcf2png utilities, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image that causes a conversion to a location "above or to the left of the canvas." NOTE: some of these details are obtained from third party information.

Alerts:
Fedora FEDORA-2010-17041 2010-10-31
Fedora FEDORA-2010-17004 2010-10-31
Fedora FEDORA-2010-17035 2010-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds