| Vulnerability Name: | CVE-2009-2295 (CCN-51570) | ||||||||||||
| Assigned: | 2009-07-02 | ||||||||||||
| Published: | 2009-07-02 | ||||||||||||
| Updated: | 2018-10-10 | ||||||||||||
| Summary: | Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function. | ||||||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-189 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2009-2295 Source: CCN Type: CamlImages Web site CamlImages Source: SECUNIA Type: UNKNOWN 35819 Source: DEBIAN Type: UNKNOWN DSA-1832 Source: DEBIAN Type: DSA-1832 camlimages -- integer overflow Source: CCN Type: GLSA-201006-02 CamlImages: User-assisted execution of arbitrary code Source: CCN Type: oCERT Advisories #2009-009 CamlImages integer overflows Source: MISC Type: UNKNOWN http://www.ocert.org/advisories/ocert-2009-009.html Source: CCN Type: OSVDB ID: 56092 CamlImages PNG Handling Multiple Functions Overflow Source: CCN Type: OSVDB ID: 56793 CamlImages gifread.c GIF File Handling Overflow Source: CCN Type: OSVDB ID: 56794 CamlImages jpegread.c JPEG File Handling Overflow Source: BUGTRAQ Type: UNKNOWN 20090702 [oCERT-2009-009] CamlImages integer overflows Source: BID Type: UNKNOWN 35556 Source: CCN Type: BID-35556 CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2009-1874 Source: XF Type: UNKNOWN camlimages-png-bo(51570) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||