10

CVE-2008-0544

Exploit
Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SdlSdl Image Version1.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.93% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://bugs.gentoo.org/show_bug.cgi?id=207933
http://secunia.com/advisories/28640
Vendor Advisory
http://secunia.com/advisories/28752
http://secunia.com/advisories/28830
http://secunia.com/advisories/28850
http://secunia.com/advisories/28869
http://secunia.com/advisories/29542
http://wiki.rpath.com/Advisories:rPSA-2008-0061
http://www.debian.org/security/2008/dsa-1493
http://www.gentoo.org/security/en/glsa/glsa-200802-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:040
http://www.securityfocus.com/archive/1/488079/100/0/threaded
http://www.ubuntu.com/usn/usn-595-1
http://www.vupen.com/english/advisories/2008/0266
https://issues.rpath.com/browse/RPL-2206
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00008.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00039.html
http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?r1=3341&r2=3521
Exploit
http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?revision=3521&view=markup
Exploit
http://www.securityfocus.com/bid/27435
https://exchange.xforce.ibmcloud.com/vulnerabilities/39899