Back to search
CVE-2012-4433
Published: Nov 18, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=856300
x_refsource_MISC
openSUSE-SU-2013:0159
vendor-advisory
x_refsource_SUSE
51114
third-party-advisory
x_refsource_SECUNIA
56404
vdb-entry
x_refsource_BID
51274
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:1455
vendor-advisory
x_refsource_REDHAT
gegl-ppm-bo(79822)
vdb-entry
x_refsource_XF
MDVSA-2013:081
vendor-advisory
x_refsource_MANDRIVA
[oss-security] 20121106 gegl: Integer overflow, leading to heap-based buffer overflow by parsing PPM image headers
mailing-list
x_refsource_MLIST
1027754
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now