FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-1948

This CVE name corresponds to:

Entered Topic
2007-04-30 p5-Imager -- possibly exploitable buffer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-1948
Phase Assigned(20070410)

Description

Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.

References

Source Reference
BUGTRAQ 20070404 Several Windows image viewers vulnerabilities
MISC http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html
VUPEN ADV-2007-1284
OSVDB 41554
SREASON 2558