Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-2295
StatusCandidate
DescriptionMultiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.
SeverityHigh
CVSS score7,5
CVSS vector(AV:N/AC:L/Au:N/C:P/I:P/A:P)
PhaseAssigned (07.07.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2295
ReferencesBUGTRAQ : 20090702 [oCERT-2009-009] CamlImages integer overflows
 MISC : http://www.ocert.org/advisories/ocert-2009-009.html
SecurityVulns:CamlImages library integer overflows

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server