CVE-2008-6079
published 2009-02-06CVE-2008-6079: imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.82%
85.0th percentile
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.4.2-1 (bookworm) | imlib2 1.4.2-1 (bookworm) |
| enlightenment | imlib2 | <= 1.4.1 | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.4.2-1 | 1.4.2-1 |
| enlightenment | imlib2 | >= 0 < 1.4.2-1 | 1.4.2-1 |
| enlightenment | imlib2 | >= 0 < 1.4.2-1 | 1.4.2-1 |
| enlightenment | imlib2 | >= 0 < 1.4.2-1 | 1.4.2-1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7hrq-pg32-qp7r: imlib2 before 1
ghsa_unreviewed·2022-05-17
CVE-2008-6079 [HIGH] GHSA-7hrq-pg32-qp7r: imlib2 before 1
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
OSV
CVE-2008-6079: imlib2 before 1
osv·2009-02-06·CVSS 10.0
CVE-2008-6079 [CRITICAL] CVE-2008-6079: imlib2 before 1
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
Red Hat
imlib2: New upstream release 1.4.2 contains security updates
vendor_redhat·2008-10-21·CVSS 10.0
CVE-2008-6079 [CRITICAL] imlib2: New upstream release 1.4.2 contains security updates
imlib2: New upstream release 1.4.2 contains security updates
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
Debian
CVE-2008-6079: imlib2 - imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified im...
vendor_debian·2008·CVSS 10.0
CVE-2008-6079 [CRITICAL] CVE-2008-6079: imlib2 - imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified im...
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
Scope: local
bookworm: resolved (fixed in 1.4.2-1)
bullseye: resolved (fixed in 1.4.2-1)
forky: resolved (fixed in 1.4.2-1)
sid: resolved (fixed in 1.4.2-1)
trixie: resolved (fixed in 1.4.2-1)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576469http://secunia.com/advisories/32354http://secunia.com/advisories/39340http://sourceforge.net/project/shownotes.php?release_id=634778http://www.debian.org/security/2010/dsa-2029http://www.securityfocus.com/bid/31880http://www.vupen.com/english/advisories/2008/2898http://www.vupen.com/english/advisories/2010/0803https://exchange.xforce.ibmcloud.com/vulnerabilities/46037http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576469http://secunia.com/advisories/32354http://secunia.com/advisories/39340http://sourceforge.net/project/shownotes.php?release_id=634778http://www.debian.org/security/2010/dsa-2029http://www.securityfocus.com/bid/31880http://www.vupen.com/english/advisories/2008/2898http://www.vupen.com/english/advisories/2010/0803https://exchange.xforce.ibmcloud.com/vulnerabilities/46037
2009-02-06
Published