Vulnerability Name: | CVE-2014-9771 (CCN-112118) | ||||||||||||||||||||||||||||
Assigned: | 2016-04-11 | ||||||||||||||||||||||||||||
Published: | 2016-04-11 | ||||||||||||||||||||||||||||
Updated: | 2016-12-01 | ||||||||||||||||||||||||||||
Summary: | Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation. CWE-190: Integer Overflow or Wraparound | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-9771 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:1330 Source: CCN Type: oss-sec Mailing List, Sun, 10 Apr 2016 00:29:48 +0200 CVE request: imlib2 integer overflow Source: DEBIAN Type: UNKNOWN DSA-3555 Source: CCN Type: Debian Bug report logs - 820206 imlib2: CVE-2014-9771: exploitable integer overflow in _imlib_SaveImage Source: CONFIRM Type: UNKNOWN https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=820206 Source: CCN Type: Red Hat Bugzilla Bug 1324774 (CVE-2014-9771) CVE-2014-9771 imlib2: exploitable integer overflow in _imlib_SaveImage Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1324774 Source: XF Type: UNKNOWN imlib2-cve20149771-overflow(112118) Source: CCN Type: imlib2 GIT Repository Make IMAGE_DIMENSIONS_OK() more restrictive Source: CONFIRM Type: UNKNOWN https://git.enlightenment.org/legacy/imlib2.git/commit/?id=143f299 Source: CONFIRM Type: UNKNOWN https://git.enlightenment.org/legacy/imlib2.git/tree/ChangeLog Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-9771 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |