CVE-2006-4809
published 2006-11-07CVE-2006-4809: Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of…
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
4.13%
89.7th percentile
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.3.0.0debian1-3 (bookworm) | imlib2 1.3.0.0debian1-3 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
| enlightenment | imlib2 | >= 0 < 1.3.0.0debian1-3 | 1.3.0.0debian1-3 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87pq-vcx3-c7wf: Stack-based buffer overflow in loader_pnm
ghsa_unreviewed·2022-05-01
CVE-2006-4809 [MEDIUM] GHSA-87pq-vcx3-c7wf: Stack-based buffer overflow in loader_pnm
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
OSV
CVE-2006-4809: Stack-based buffer overflow in loader_pnm
osv·2006-11-07·CVSS 5.1
CVE-2006-4809 [MEDIUM] CVE-2006-4809: Stack-based buffer overflow in loader_pnm
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
Ubuntu
imlib2 vulnerabilities
vendor_ubuntu·2006-11-03
CVE-2006-4806 imlib2 vulnerabilities
Title: imlib2 vulnerabilities
Summary: imlib2 vulnerabilities
M. Joonas Pihlaja discovered that imlib2 did not sufficiently verify the
validity of ARGB, JPG, LBM, PNG, PNM, TGA, and TIFF images. If a user
were tricked into viewing or processing a specially crafted image with
an application that uses imlib2, the flaws could be exploited to execute
arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-4809: imlib2 - Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly...
vendor_debian·2006·CVSS 5.1
CVE-2006-4809 [MEDIUM] CVE-2006-4809: imlib2 - Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly...
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3.0.0debian1-3)
sid: resolved (fixed in 1.3.0.0debian1-3)
trixie: resolved (fixed in 1.3.0.0debian1-3)
Red Hat
CVE-2006-4809: Stack-based buffer overflow in loader_pnm
vendor_redhat·CVSS 5.1
CVE-2006-4809 [MEDIUM] CVE-2006-4809: Stack-based buffer overflow in loader_pnm
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 do not include imlib2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
bugzilla·2008-05-30·CVSS 5.1
CVE-2008-2426 [MEDIUM] CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
Stefan Cornelius of the Secunia Research discovered and reported following
issues affecting imlib2's PNM and XPM loaders:
1) A boundary error exists within the "load()" function in
src/modules/loaders/loader_pnm.c when processing the header of a
PNM image file. This can be exploited to cause a stack-based buffer
overflow by e.g. tricking a user into opening a specially crafted
PNM image in an application using the imlib2 library.
Successful exploitation allows execution of arbitrary code.
2) A boundary error exists within the "load()" function in
src/modules/loader_xpm.c when processing an XPM image file. This can
be exploited to cause a stack-based buffer overflow by e.g. tricking
a user into opening a specially crafted XPM
Bugzilla
CVE-2006-480[6-9] imlib2 multiple vulnerabilities
bugzilla·2006-11-08·CVSS 5.1
CVE-2006-4806 [MEDIUM] CVE-2006-480[6-9] imlib2 multiple vulnerabilities
CVE-2006-480[6-9] imlib2 multiple vulnerabilities
Multiple vulnerabilities in imlib2:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4806
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4807
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4808
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4809
Some of the reports mention "before 1.2.1", but at least some of the issues seem
to be present in 1.2.2 and 1.3.0 too.
FreeBSD's patches (apparently originally from Ubuntu) for these issues are
available at http://www.freebsd.org/cgi/cvsweb.cgi/ports/graphics/imlib2/files/
Discussion:
Thanks for reporting this. I've pushed imlib2 updates for FC-3 - FC-6 and devel
and I'll start writing an advisory right away.
http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30104http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30070http://secunia.com/advisories/22732http://secunia.com/advisories/22744http://secunia.com/advisories/22752http://secunia.com/advisories/22932http://secunia.com/advisories/23441http://security.gentoo.org/glsa/glsa-200612-20.xmlhttp://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gzhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:198http://www.mandriva.com/security/advisories?name=MDKSA-2007:156http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/30104http://www.securityfocus.com/bid/20903http://www.ubuntu.com/usn/usn-376-1http://www.ubuntu.com/usn/usn-376-2http://www.vupen.com/english/advisories/2006/4349https://exchange.xforce.ibmcloud.com/vulnerabilities/30070
2006-11-07
Published