Executive Summary

Summary
TitleNew netpbm-free packages fix denial of service
Informations
NameDSA-2026First vendor Publication2010-04-02
VendorDebianLast vendor Modification2010-04-02
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Marc Schoenefeld discovered a stack-based buffer overflow in the XPM reader implementation in netpbm-free, a suite of image manipulation utilities. An attacker could cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.



For the stable distribution (lenny), this problem has been fixed in version 2:10.0-12+lenny1.

For the testing distribution (squeeze), this problem has been fixed in version 2:10.0-12.1+squeeze1.

For the unstable distribution (sid), this problem will be fixed soon.



Due to a problem with the archive system it is not possible to release all architectures. The missing architectures will be installed into the archive once they become available.

We recommend that you upgrade your netpbm-free package.

Original Source

Url : http://www.debian.org/security/2010/dsa-2026

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application101

Open Source Vulnerability Database (OSVDB)

idDescription
62270NetPBM xpmtoppm XPM File Handling Overflow