NASLDB: SuSE Security Update: imlib2: Fixed various security problems in imlib2-loaders (imlib2-loaders-2265)
General
ID: 27271
Name: SuSE Security Update: imlib2: Fixed various security problems in imlib2-loaders (imlib2-loaders-2265)
Summary: Check for the imlib2-loaders-2265 package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: SuSE Local Security Checks
Type: –
Description
Various security problems have been fixed in the imlib2
image loaders:
CVE-2006-4809: A stack buffer overflow in loader_pnm.c
could be used by attackers to execute code by supplying a
handcrafted PNM image.
CVE-2006-4808: A heap buffer overflow in loader_tga.c could
potentially be used by attackers to execute code by
supplying a handcrafted TGA image.
CVE-2006-4807: A out of bounds memory read in loader_tga.c
could be used to crash the imlib2 using application with a
handcrafted TGA image.
CVE-2006-4806: Various integer overflows in width*height
calculations could lead to heap overflows which could
potentially be used to execute code. Affected here are the
ARGB, PNG, LBM, JPEG and TIFF loaders.
Additionaly loading of TIFF images on 64bit systems is now
possible.
This update obsoletes the previous one, which had problems
with JPEG loading.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2006-4809
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2007/10/17
Plugin
Version: 1.7
Filename: suse_imlib2-loaders-2265.nasl
Filesize: 2574 bytes
MD5 Hash: 5c6e5ec3c0dfb1467bb7aa369c3dafc3
Identification: Host/SuSE/rpm-list
Require Keys: Host/SuSE/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2007-2010 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













