CVE-2008-2426
published 2008-06-02CVE-2008-2426: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.75%
92.2th percentile
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| carsten_haitzler | imlib2 | — | — |
| debian | imlib2 | < imlib2 1.4.0-1.2 (bookworm) | imlib2 1.4.0-1.2 (bookworm) |
| debian | imlib2 | < imlib2 1.4.0-1.1 (bookworm) | imlib2 1.4.0-1.1 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.1 | 1.4.0-1.1 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.1 | 1.4.0-1.1 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.1 | 1.4.0-1.1 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.1 | 1.4.0-1.1 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Imlib2 vulnerability
vendor_ubuntu·2008-12-22
CVE-2008-2426 Imlib2 vulnerability
Title: Imlib2 vulnerability
Summary: Imlib2 vulnerability
It was discovered that Imlib2 did not correctly handle certain malformed XPM
and PNG images. If a user were tricked into opening a specially crafted image
with an application that uses Imlib2, an attacker could cause a denial of
service and possibly execute arbitrary code with the user's privileges.
Instructions: After a standard system upgrade you need to restart any applications that
use Imlib2 to effect the necessary changes.
Red Hat
imilb2: pointer arithmetic flaw in XPM loader
vendor_redhat·2008-11-14·CVSS 9.3
CVE-2008-5187 [CRITICAL] imilb2: pointer arithmetic flaw in XPM loader
imilb2: pointer arithmetic flaw in XPM loader
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Statement: Not vulnerable. This issue does not affect the versions of imlib as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
Red Hat
imlib2: buffer overflows in PNM and XPM loaders
vendor_redhat·2008-05-29·CVSS 9.3
CVE-2008-2426 [CRITICAL] imlib2: buffer overflows in PNM and XPM loaders
imlib2: buffer overflows in PNM and XPM loaders
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.
Debian
CVE-2008-5187: imlib2 - The load function in the XPM loader for imlib2 1.4.2, and possibly other version...
vendor_debian·2008·CVSS 9.3
CVE-2008-5187 [CRITICAL] CVE-2008-5187: imlib2 - The load function in the XPM loader for imlib2 1.4.2, and possibly other version...
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Scope: local
bookworm: resolved (fixed in 1.4.0-1.2)
bullseye: resolved (fixed in 1.4.0-1.2)
forky: resolved (fixed in 1.4.0-1.2)
sid: resolved (fixed in 1.4.0-1.2)
trixie: resolved (fixed in 1.4.0-1.2)
Debian
CVE-2008-2426: imlib2 - Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-a...
vendor_debian·2008·CVSS 9.3
CVE-2008-2426 [CRITICAL] CVE-2008-2426: imlib2 - Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-a...
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.
Scope: local
bookworm: resolved (fixed in 1.4.0-1.1)
bullseye: resolved (fixed in 1.4.0-1.1)
forky: resolved (fixed in 1.4.0-1.1)
sid: resolved (fixed in 1.4.0-1.1)
trixie: resolved (fixed in 1.4.0-1.1)
GHSA
GHSA-793h-w8mx-wf86: The load function in the XPM loader for imlib2 1
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2008-5187 [CRITICAL] CWE-119 GHSA-793h-w8mx-wf86: The load function in the XPM loader for imlib2 1
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
GHSA
GHSA-vp39-rwgc-h3pg: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1
ghsa_unreviewed·2022-05-01
CVE-2008-2426 [HIGH] CWE-119 GHSA-vp39-rwgc-h3pg: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.
OSV
CVE-2008-5187: The load function in the XPM loader for imlib2 1
osv·2008-11-21·CVSS 9.3
CVE-2008-5187 [CRITICAL] CVE-2008-5187: The load function in the XPM loader for imlib2 1
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
OSV
CVE-2008-2426: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1
osv·2008-06-02·CVSS 9.3
CVE-2008-2426 [CRITICAL] CVE-2008-2426: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5187 imilb2: pointer arithmetic flaw in XPM loader
bugzilla·2008-11-21·CVSS 9.3
CVE-2008-5187 [CRITICAL] CVE-2008-5187 imilb2: pointer arithmetic flaw in XPM loader
CVE-2008-5187 imilb2: pointer arithmetic flaw in XPM loader
The load function in the XPM loader for imlib2 1.4.2, and possibly other
versions, allows attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a crafted XPM file that triggers a
"pointer arithmetic error" and a heap-based buffer overflow, a different
vulnerability than CVE-2008-2426.
NOTE: the provenance of this information is unknown; the details are
obtained solely from third party information.
http://www.openwall.com/lists/oss-security/2008/11/20/5
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505714#15
http://secunia.com/advisories/32796
Discussion:
imlib2-1.4.2-2.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/imlib2-1.4.2-2.fc10
---
imlib2
Bugzilla
CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
bugzilla·2008-05-30·CVSS 5.1
CVE-2008-2426 [MEDIUM] CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
CVE-2008-2426 imlib2: buffer overflows in PNM and XPM loaders
Stefan Cornelius of the Secunia Research discovered and reported following
issues affecting imlib2's PNM and XPM loaders:
1) A boundary error exists within the "load()" function in
src/modules/loaders/loader_pnm.c when processing the header of a
PNM image file. This can be exploited to cause a stack-based buffer
overflow by e.g. tricking a user into opening a specially crafted
PNM image in an application using the imlib2 library.
Successful exploitation allows execution of arbitrary code.
2) A boundary error exists within the "load()" function in
src/modules/loader_xpm.c when processing an XPM image file. This can
be exploited to cause a stack-based buffer overflow by e.g. tricking
a user into opening a specially crafted XPM
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/30401http://secunia.com/advisories/30485http://secunia.com/advisories/30572http://secunia.com/advisories/30727http://secunia.com/advisories/31982http://secunia.com/secunia_research/2008-25/advisory/http://securitytracker.com/id?1020146http://www.debian.org/security/2008/dsa-1594http://www.gentoo.org/security/en/glsa/glsa-200806-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:123http://www.securityfocus.com/archive/1/492739/100/0/threadedhttp://www.securityfocus.com/bid/29417http://www.ubuntu.com/usn/USN-697-1http://www.vupen.com/english/advisories/2008/1700https://exchange.xforce.ibmcloud.com/vulnerabilities/42732https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00030.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00052.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00113.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/30401http://secunia.com/advisories/30485http://secunia.com/advisories/30572http://secunia.com/advisories/30727http://secunia.com/advisories/31982http://secunia.com/secunia_research/2008-25/advisory/http://securitytracker.com/id?1020146http://www.debian.org/security/2008/dsa-1594http://www.gentoo.org/security/en/glsa/glsa-200806-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:123http://www.securityfocus.com/archive/1/492739/100/0/threadedhttp://www.securityfocus.com/bid/29417http://www.ubuntu.com/usn/USN-697-1http://www.vupen.com/english/advisories/2008/1700https://exchange.xforce.ibmcloud.com/vulnerabilities/42732https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00030.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00052.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00113.html
2008-06-02
Published