LWN.net Logo

gif2png: arbitrary code execution

Package(s):gif2png CVE #(s):CVE-2009-5018
Created:January 5, 2011 Updated:January 17, 2011
Description: From the Gentoo advisory:

gif2png contains a command line parsing vulnerability that may result in a stack overflow due to an unexpectedly long input filename.

A remote attacker could entice a user to open a specially crafted image, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service. Note that applications relying on gif2png to process images can also trigger the vulnerability.

Alerts:
Gentoo 201101-01 2011-01-05
Mandriva MDVSA-2011:009 2011-01-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds