access granted
Showing 1 - 1 of 1 RSS Feed

Files

Open Source CERT Security Advisory 2009.9
Posted Jul 2, 2009
Authored by Andrea Barisani, Open Source CERT | Site ocert.org

CamlImages versions 2.2 and below suffer from several integer overflows which may lead to a potentially exploitable heap overflow and result in arbitrary code execution. The vulnerability is triggered by PNG image parsing, the read_png_file and read_png_file_as_rgb24 functions do not properly validate the width and height of the image. Specific PNG images with large width and height can be crafted to trigger the vulnerability.

tags | advisory, overflow, arbitrary, code execution
advisories | CVE-2009-2295
MD5 | 4fa5917b93622cf557fa89435814a10b
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2011 Packet Storm. All rights reserved.

close