CVE-2008-0553Improper Restriction of Operations within the Bounds of a Memory Buffer in Libtk-img

Severity
6.8MEDIUMNVD
OSV2.6
EPSS
6.0%
top 9.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateMay 1

Description

Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

debiandebian/libtk-img< libtk-img 1:1.3-release-7 (bookworm)
NVDtcl_tk/tcl_tk8.4.17+68

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w2px-74cm-hrpr: Stack-based buffer overflow in the ReadImage function in tkImgGIF2022-05-01
OSV
CVE-2008-0553: Stack-based buffer overflow in the ReadImage function in tkImgGIF2008-02-07

📋Vendor Advisories

4
Ubuntu
Tk vulnerability2008-11-06
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues2008-06-04
Red Hat
tk: GIF handling buffer overflow2008-02-01
Debian
CVE-2008-0553: libtk-img - Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/T...2008

💬Community

7
Bugzilla
CVE-2011-2896 David Koblas' GIF decoder LZW decoder buffer overflow2011-08-03
Bugzilla
CVE-2011-2897 gdk-pixbuf: GIF loader buffer overflow when initializing decompression tables2011-08-01
Bugzilla
CVE-2008-1373 cups: overflow in gif image filter2008-03-20
Bugzilla
CVE-2008-0553 tk: GIF handling buffer overflow2008-02-05
Bugzilla
CVE-2008-0553 tk: GIF handling buffer overflow [rawhide]2008-02-05
CVE-2008-0553 — Debian Libtk-img vulnerability | cvebase