CVE-2006-4808
published 2006-11-07CVE-2006-4808: Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of…
PriorityP423low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
4.13%
89.7th percentile
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.3.0.0debian1-3 (bookworm) | imlib2 1.3.0.0debian1-3 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6MEDIUM
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
imlib2 vulnerabilities
vendor_ubuntu·2006-11-03
CVE-2006-4806 imlib2 vulnerabilities
Title: imlib2 vulnerabilities
Summary: imlib2 vulnerabilities
M. Joonas Pihlaja discovered that imlib2 did not sufficiently verify the
validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images. If a user
were tricked into viewing or processing a specially crafted image with
an application that uses imlib2, the flaws could be exploited to execute
arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-4808: imlib2 - Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly ...
vendor_debian·2006·CVSS 2.6
CVE-2006-4808 [LOW] CVE-2006-4808: imlib2 - Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly ...
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3.0.0debian1-3)
sid: resolved (fixed in 1.3.0.0debian1-3)
trixie: resolved (fixed in 1.3.0.0debian1-3)
Debian
CVE-2006-4807: imlib2 - loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-as...
vendor_debian·2006·CVSS 2.6
CVE-2006-4807 [LOW] CVE-2006-4807: imlib2 - loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-as...
loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3.0.0debian1-3)
sid: resolved (fixed in 1.3.0.0debian1-3)
trixie: resolved (fixed in 1.3.0.0debian1-3)
Red Hat
CVE-2006-4807: loader_tga
vendor_redhat·CVSS 2.6
CVE-2006-4807 [LOW] CVE-2006-4807: loader_tga
loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 do not include imlib2.
Red Hat
CVE-2006-4808: Heap-based buffer overflow in loader_tga
vendor_redhat·CVSS 2.6
CVE-2006-4808 [LOW] CVE-2006-4808: Heap-based buffer overflow in loader_tga
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 do not include imlib2.
GHSA
GHSA-qw58-8vpf-jmmg: loader_tga
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2006-4807 [LOW] GHSA-qw58-8vpf-jmmg: loader_tga
loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.
GHSA
GHSA-hcr5-cf9m-7gf4: Heap-based buffer overflow in loader_tga
ghsa_unreviewed·2022-05-01
CVE-2006-4808 [LOW] GHSA-hcr5-cf9m-7gf4: Heap-based buffer overflow in loader_tga
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
OSV
CVE-2006-4807: loader_tga
osv·2006-11-07·CVSS 2.6
CVE-2006-4807 [LOW] CVE-2006-4807: loader_tga
loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.
OSV
CVE-2006-4808: Heap-based buffer overflow in loader_tga
osv·2006-11-07·CVSS 2.6
CVE-2006-4808 [LOW] CVE-2006-4808: Heap-based buffer overflow in loader_tga
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
No detection rules found.
http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30103http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30068http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30103http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30068
2006-11-07
Published