FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1060

This CVE name corresponds to:

Entered Topic
2006-04-23 zgv, xzgv -- heap overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1060
Phase Assigned(20060307)

Description

Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.

References

Source Reference
DEBIAN DSA-1037
DEBIAN DSA-1038
SUSE SUSE-SR:2006:008
BID 17409
VUPEN ADV-2006-1288
SECUNIA 19572
SECUNIA 19571
SECUNIA 19731
SECUNIA 19757
SECUNIA 19779
SECUNIA 19790
SREASON 756
XF xzgv-jpeg-bo(25718)