*** This bug is a security vulnerability ***

Public security bug reported:

CVE-2008-0554 description:

"Buffer overflow in the readImageData function in giftopnm.c in netpbm
before 10.27 in netpbm before 10.27 allows remote user-assisted
attackers to cause a denial of service (crash) and possibly execute
arbitrary code via a crafted GIF image, a similar issue to
CVE-2006-4484."

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0554

Debian advisory DSA 1579-1:
http://www.debian.org/security/2008/dsa-1579

This has been fixed in Hardy but previous releases seem to be
vulnerable.

** Affects: netpbm-free (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: netpbm-free (Debian)
     Importance: Unknown
         Status: Fix Released

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-0554

** Bug watch added: Debian Bug tracker #464056
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464056

** Also affects: netpbm-free (Debian) via
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464056
   Importance: Unknown
       Status: Unknown

-- 
[CVE-2008-0554] Buffer overflow in readImageData() in giftopnm.c leads to 
arbitrary code execution
https://bugs.launchpad.net/bugs/232156
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to