Debian Netpbm-Free vulnerabilities
19 known vulnerabilities affecting debian/netpbm-free.
Total CVEs
19
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM7LOW10
Vulnerabilities
Page 1 of 1
CVE-2018-8975LOWCVSS 5.52018
CVE-2018-8975 [MEDIUM] CVE-2018-8975: netpbm-free - The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 ...
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2017-2581MEDIUMCVSS 4.5fixed in netpbm-free 2:10.97.00-1 (bookworm)2017
CVE-2017-2581 [MEDIUM] CVE-2017-2581: netpbm-free - An out-of-bounds write vulnerability was found in netpbm before 10.61. A malicio...
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Scope: local
bookworm: resolved (fixed in 2:10.97.00-1)
bullseye: resolved
forky: resolved (fixed in 2:10.97.00-1)
sid: resolved (fixed in 2:10.97.00-1)
trixie: resolved (fixed in 2:10.97.00-1)
debian
CVE-2017-2580MEDIUMCVSS 4.5fixed in netpbm-free 2:10.97.00-1 (bookworm)2017
CVE-2017-2580 [MEDIUM] CVE-2017-2580: netpbm-free - An out-of-bounds write vulnerability was found in netpbm before 10.61. A malicio...
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Scope: local
bookworm: resolved (fixed in 2:10.97.00-1)
bullseye: resolved
forky: resolved (fixed in 2:10.97.00-1)
sid: resolved (fixed in 2:10.97.00-1)
trixie: resolved (fixed in 2:10.97.00-1)
debian
CVE-2017-2586LOWCVSS 3.32017
CVE-2017-2586 [LOW] CVE-2017-2586: netpbm-free - A null pointer dereference vulnerability was found in netpbm before 10.61. A mal...
A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2017-2587LOWCVSS 3.32017
CVE-2017-2587 [LOW] CVE-2017-2587: netpbm-free - A memory allocation vulnerability was found in netpbm before 10.61. A maliciousl...
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2017-5849LOWCVSS 5.52017
CVE-2017-5849 [MEDIUM] CVE-2017-5849: netpbm-free - tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet...
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2017-2579LOWCVSS 3.3fixed in netpbm-free 2:10.97.00-1 (bookworm)2017
CVE-2017-2579 [LOW] CVE-2017-2579: netpbm-free - An out-of-bounds read vulnerability was found in netpbm before 10.61. The expand...
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.
Scope: local
bookworm: resolved (fixed in 2:10.97.00-1)
bullseye: resolved
forky: resolved (fixed in 2:10.97.00-1)
si
debian
CVE-2009-4274MEDIUMCVSS 7.5fixed in netpbm-free 2:10.0-12.2 (bookworm)2009
CVE-2009-4274 [HIGH] CVE-2009-4274: netpbm-free - Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.0...
Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.
Scope: local
bookworm: resolved (fixed in 2:10.0-12.2)
bullseye
debian
CVE-2008-3522MEDIUMCVSS 10.0fixed in ghostscript 8.64~dfsg-2 (bookworm)2008
CVE-2008-3522 [CRITICAL] CVE-2008-3522: ghostscript - Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c...
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullseye: resolved (fixed in 8.64~dfsg-2)
forky: resolved (fixed in 8.64~
debian
CVE-2008-0554MEDIUMCVSS 2.6fixed in netpbm-free 10.0-11.1 (bookworm)2008
CVE-2008-0554 [LOW] CVE-2008-0554: netpbm-free - Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10....
Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
Scope: local
bookworm: resolved (fixed in 10.0-11.1)
bullseye: resolved (fixed in 10.0-11.1
debian
CVE-2008-3520LOWCVSS 9.3fixed in ghostscript 8.64~dfsg-2 (bookworm)2008
CVE-2008-3520 [CRITICAL] CVE-2008-3520: ghostscript - Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attac...
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullseye: resolved (fixed in 8.64~dfsg-2)
forky: resolved (fixed in 8.64~dfsg-2)
sid: resolved (fixed in 8.64~dfs
debian
CVE-2008-4799LOWCVSS 4.32008
CVE-2008-4799 [MEDIUM] CVE-2008-4799: netpbm-free - pamperspective in Netpbm before 10.35.48 does not properly calculate a window he...
pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2006-3145LOWCVSS 5.02006
CVE-2006-3145 [MEDIUM] CVE-2006-3145: netpbm-free - Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attacke...
Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2005-2978HIGHCVSS 7.5fixed in netpbm-free 2:10.0-10 (bookworm)2005
CVE-2005-2978 [HIGH] CVE-2005-2978: netpbm-free - pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialize...
pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.
Scope: local
bookworm: resolved (fixed in 2:10.0-10)
bullseye: resolved (fixed in 2:10.0-10)
forky:
debian
CVE-2005-3662MEDIUMCVSS 4.6fixed in netpbm-free 2:10.0-10.1 (bookworm)2005
CVE-2005-3662 [MEDIUM] CVE-2005-3662: netpbm-free - Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha comman...
Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.
Scope: local
bookworm: resolved (fixed in 2:10.0-10.1)
bullseye: resolved (fixed in 2:10.0-10.1)
forky: resolved
debian
CVE-2005-3632MEDIUMCVSS 4.6fixed in netpbm-free 2:10.0-10.1 (bookworm)2005
CVE-2005-3632 [MEDIUM] CVE-2005-3632: netpbm-free - Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers...
Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers to execute arbitrary code via a crafted PNM file.
Scope: local
bookworm: resolved (fixed in 2:10.0-10.1)
bullseye: resolved (fixed in 2:10.0-10.1)
forky: resolved (fixed in 2:10.0-10.1)
sid: resolved (fixed in 2:10.0-10.1)
trixie: resolved (fixed in 2:10.0-10.1)
debian
CVE-2005-2471LOWCVSS 7.5fixed in netpbm-free 2:10.0-9 (bookworm)2005
CVE-2005-2471 [HIGH] CVE-2005-2471: netpbm-free - pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghosts...
pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.
Scope: local
bookworm: resolved (fixed in 2:10.0-9)
bullseye: resolved (fixed in 2:10.0-9)
forky: resolved (fixed in 2:10.0-9)
sid:
debian
CVE-2003-0146HIGHCVSS 7.5fixed in lpr 1:2000.05.07-4.20 (bookworm)2003
CVE-2003-0146 [HIGH] CVE-2003-0146: lpr - Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions...
Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.
Scope: local
bookworm: resolved (fixed in 1:2000.05.07-4.20)
bullseye: resolved (fixed
debian
CVE-2003-0924LOWCVSS 3.7fixed in netpbm-free 2:9.25-9 (bookworm)2003
CVE-2003-0924 [LOW] CVE-2003-0924: netpbm-free - netpbm 9.25 and earlier does not properly create temporary files, which allows l...
netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
Scope: local
bookworm: resolved (fixed in 2:9.25-9)
bullseye: resolved (fixed in 2:9.25-9)
forky: resolved (fixed in 2:9.25-9)
sid: resolved (fixed in 2:9.25-9)
trixie: resolved (fixed in 2:9.25-9)
debian