CVE Database
/

CVE-2006-1060

Back to search

CVE-2006-1060

Published: Apr 11, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.

VendorProductVersions

n/a

n/a

affected
n/a

References

17409
vdb-entry
x_refsource_BID
19572
third-party-advisory
x_refsource_SECUNIA
19779
third-party-advisory
x_refsource_SECUNIA
19790
third-party-advisory
x_refsource_SECUNIA
ADV-2006-1288
vdb-entry
x_refsource_VUPEN
19757
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:008
vendor-advisory
x_refsource_SUSE
xzgv-jpeg-bo(25718)
vdb-entry
x_refsource_XF
DSA-1037
vendor-advisory
x_refsource_DEBIAN
19731
third-party-advisory
x_refsource_SECUNIA
756
third-party-advisory
x_refsource_SREASON
19571
third-party-advisory
x_refsource_SECUNIA
DSA-1038
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now