7.5
CVSSv2

CVE-2016-4024

Published: 13/05/2016 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in imlib2 prior to 1.4.9 on 32-bit platforms allows remote malicious users to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.

Vulnerable Product Search on Vulmon Subscribe to Product

enlightenment imlib2

debian debian linux 7.0

opensuse opensuse 13.2

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in Imlib2 ...
Several vulnerabilities were discovered in imlib2, an image manipulation library CVE-2011-5326 Kevin Ryde discovered that attempting to draw a 2x1 radi ellipse results in a floating point exception CVE-2014-9771 It was discovered that an integer overflow could lead to invalid memory reads and unreasonably large memory allocations ...
Debian Bug report logs - #785369 imlib2: CVE-2016-3994: GIF loader: out-of-bounds read Package: libimlib2; Maintainer for libimlib2 is Markus Koschany <apo@debianorg>; Source for libimlib2 is src:imlib2 (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Fri, 15 May 2015 11:24:01 UTC Severity: im ...
Debian Bug report logs - #639414 imlib2: CVE-2011-5326: divide-by-zero on 2x1 ellipse Package: libimlib2; Maintainer for libimlib2 is Markus Koschany <apo@debianorg>; Source for libimlib2 is src:imlib2 (PTS, buildd, popcon) Reported by: Kevin Ryde <user42_kevin@yahoocomau> Date: Fri, 26 Aug 2011 23:45:01 UTC Seve ...
Debian Bug report logs - #820206 imlib2: CVE-2014-9771: exploitable integer overflow in _imlib_SaveImage Package: src:imlib2; Maintainer for src:imlib2 is Markus Koschany <apo@debianorg>; Reported by: "Yuriy M Kaminskiy" <yumkam@gmailcom> Date: Wed, 6 Apr 2016 15:09:09 UTC Severity: important Tags: fixed-upstream ...
Debian Bug report logs - #821732 CVE-2016-4024: integer overflow resulting in insufficient heap allocation Package: src:imlib2; Maintainer for src:imlib2 is Markus Koschany <apo@debianorg>; Reported by: Matthias Geerdsen <matthias@vorlonsinfo> Date: Mon, 18 Apr 2016 21:51:02 UTC Severity: normal Tags: fixed-upstrea ...
Debian Bug report logs - #819818 imlib2: CVE-2016-3993: off-by-one OOB read in __imlib_MergeUpdate Package: libimlib2; Maintainer for libimlib2 is Markus Koschany <apo@debianorg>; Source for libimlib2 is src:imlib2 (PTS, buildd, popcon) Reported by: "Yuriy M Kaminskiy" <yumkam@gmailcom> Date: Sat, 2 Apr 2016 18:2 ...