6.8
CVSSv2

CVE-2010-1513

Published: 26/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in src/image.c in Ziproxy prior to 3.0.1 allow remote malicious users to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.

Vulnerable Product Search on Vulmon Subscribe to Product

daniel mealha cabrita ziproxy 2.7.1

daniel mealha cabrita ziproxy 2.7.0

daniel mealha cabrita ziproxy 2.3.0

daniel mealha cabrita ziproxy 2.2.2

daniel mealha cabrita ziproxy 1.5.1

daniel mealha cabrita ziproxy 1.5.0

daniel mealha cabrita ziproxy 1.2

daniel mealha cabrita ziproxy 2.6.9

daniel mealha cabrita ziproxy 2.5.9

daniel mealha cabrita ziproxy 2.5.1

daniel mealha cabrita ziproxy 2.5.0

daniel mealha cabrita ziproxy 2.2.1

daniel mealha cabrita ziproxy 2.2.0

daniel mealha cabrita ziproxy 2.1.1

daniel mealha cabrita ziproxy 1.4.0

daniel mealha cabrita ziproxy 1.3

daniel mealha cabrita ziproxy 1.1

daniel mealha cabrita ziproxy

daniel mealha cabrita ziproxy 2.4.8

daniel mealha cabrita ziproxy 2.5.2

daniel mealha cabrita ziproxy 2.7.2

daniel mealha cabrita ziproxy 2.4.1

daniel mealha cabrita ziproxy 2.4.0

daniel mealha cabrita ziproxy 1.9.0

daniel mealha cabrita ziproxy 1.5.2

daniel mealha cabrita ziproxy 2.7.9

daniel mealha cabrita ziproxy 2.6.0

daniel mealha cabrita ziproxy 2.4.3

daniel mealha cabrita ziproxy 2.4.2

daniel mealha cabrita ziproxy 2.1.0

daniel mealha cabrita ziproxy 2.0.0

daniel mealha cabrita ziproxy 3.0.1

daniel mealha cabrita ziproxy 2.3.5

Vendor Advisories

Debian Bug report logs - #584933 CVE-2010-1513 Package: ziproxy; Maintainer for ziproxy is Marcos Talau <talau@userssourceforgenet>; Source for ziproxy is src:ziproxy (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 7 Jun 2010 16:21:05 UTC Severity: grave Tags: security Fixed in ...