2.6
CVSSv2

CVE-2006-4807

Published: 07/11/2006 Updated: 20/07/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

loader_tga.c in imlib2 prior to 1.2.1, and possibly other versions, allows user-assisted remote malicious users to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.

Vulnerable Product Search on Vulmon Subscribe to Product

enlightenment imlib2 1.0.5

enlightenment imlib2 1.1

enlightenment imlib2 1.0.3

enlightenment imlib2 1.0.4

enlightenment imlib2 1.0.1

enlightenment imlib2 1.0.2

enlightenment imlib2 1.0

enlightenment imlib2 1.1.1

enlightenment imlib2 1.1.2

Vendor Advisories

M Joonas Pihlaja discovered that imlib2 did not sufficiently verify the validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images If a user were tricked into viewing or processing a specially crafted image with an application that uses imlib2, the flaws could be exploited to execute arbitrary code with the user’s privileges ...