FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5101

This CVE name corresponds to:

Entered Topic
2009-01-19 optipng -- arbitrary code execution via crafted BMP image

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5101
Phase Assigned(20081117)

Description

Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted attackers to execute arbitrary code via a crafted BMP image, related to an "array overflow."

References

Source Reference
MLIST [oss-security] 20081112 CVE Request -- OptiPNG
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505399
CONFIRM http://optipng.sourceforge.net/
CONFIRM http://prdownloads.sourceforge.net/optipng/optipng-0.6.1.1.diff?download
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=639631&group_id=151404
GENTOO GLSA-200812-01
SUSE SUSE-SR:2009:006
BID 32248
SECUNIA 34259
VUPEN ADV-2008-3108
SECUNIA 32651
XF optipng-bmpreader-bo(46519)