FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

tcl/tk -- buffer overflow in ReadImage function

Affected packages
tcl < 8.4.16
8.4.*,1 < tcl < 8.4.16,1
tcl-threads < 8.4.16
8.4.*,1 < tcl-threads < 8.4.16,1
tk < 8.4.16
8.4.*,2 < tk < 8.4.16,2
tk-threads < 8.4.16
8.4.*,2 < tk-threads < 8.4.16,2

Details

VuXML ID a058d6fa-7325-11dc-ae10-0016179b2dd5
Discovery 2007-09-27
Entry 2007-10-05
Modified 2007-12-31

A Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl/Tk, allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first.

References

CVE Name CVE-2007-5137
URL http://secunia.com/advisories/26942
URL http://sourceforge.net/project/shownotes.php?release_id=541207