7.5
CVSSv2

CVE-2008-5187

Published: 21/11/2008 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.

Vulnerable Product Search on Vulmon Subscribe to Product

enlightenment imlib2 1.4.2

Vendor Advisories

Debian Bug report logs - #505714 Crash on loading XPM file Package: libimlib2; Maintainer for libimlib2 is Markus Koschany <apo@debianorg>; Source for libimlib2 is src:imlib2 (PTS, buildd, popcon) Reported by: Julien Danjou <acid@debianorg> Date: Fri, 14 Nov 2008 15:09:02 UTC Severity: grave Tags: patch, security ...
It was discovered that Imlib2 did not correctly handle certain malformed XPM images If a user were tricked into opening a specially crafted image with an application that uses Imlib2, an attacker could cause a denial of service and possibly execute arbitrary code with the user’s privileges ...