CVE-2006-4806
published 2006-11-07CVE-2006-4806: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a…
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
4.21%
89.8th percentile
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.3.0.0debian1-3 (bookworm) | imlib2 1.3.0.0debian1-3 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5hx6-59g5-f27r: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
ghsa_unreviewed·2022-05-01
CVE-2006-4806 [MEDIUM] GHSA-5hx6-59g5-f27r: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
OSV
CVE-2006-4806: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
osv·2006-11-07·CVSS 5.1
CVE-2006-4806 [MEDIUM] CVE-2006-4806: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
Ubuntu
imlib2 vulnerabilities
vendor_ubuntu·2006-11-03
CVE-2006-4806 imlib2 vulnerabilities
Title: imlib2 vulnerabilities
Summary: imlib2 vulnerabilities
M. Joonas Pihlaja discovered that imlib2 did not sufficiently verify the
validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images. If a user
were tricked into viewing or processing a specially crafted image with
an application that uses imlib2, the flaws could be exploited to execute
arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-4806: imlib2 - Multiple integer overflows in imlib2 allow user-assisted remote attackers to cau...
vendor_debian·2006·CVSS 5.1
CVE-2006-4806 [MEDIUM] CVE-2006-4806: imlib2 - Multiple integer overflows in imlib2 allow user-assisted remote attackers to cau...
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3.0.0debian1-3)
sid: resolved (fixed in 1.3.0.0debian1-3)
trixie: resolved (fixed in 1.3.0.0debian1-3)
Red Hat
CVE-2006-4806: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
vendor_redhat·CVSS 5.1
CVE-2006-4806 [MEDIUM] CVE-2006-4806: Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 do not include imlib2.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30105http://www.osvdb.org/30106http://www.osvdb.org/30107http://www.osvdb.org/30108http://www.osvdb.org/30109http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30064http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30105http://www.osvdb.org/30106http://www.osvdb.org/30107http://www.osvdb.org/30108http://www.osvdb.org/30109http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30064
2006-11-07
Published