5.1
CVSSv2

CVE-2006-4806

Published: 07/11/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in imlib2 allow user-assisted remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.

Vulnerable Product Search on Vulmon Subscribe to Product

enlightenment imlib2 1.0.2

enlightenment imlib2 1.0.3

enlightenment imlib2 1.2.2

enlightenment imlib2 1.3

enlightenment imlib2 1.0

enlightenment imlib2 1.0.1

enlightenment imlib2 1.1.2

enlightenment imlib2 1.2.1

enlightenment imlib2 1.1

enlightenment imlib2 1.1.1

enlightenment imlib2 1.0.4

enlightenment imlib2 1.0.5

Vendor Advisories

M Joonas Pihlaja discovered that imlib2 did not sufficiently verify the validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images If a user were tricked into viewing or processing a specially crafted image with an application that uses imlib2, the flaws could be exploited to execute arbitrary code with the user’s privileges ...