Vulnerability Description
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enlightenment | Imlib2 | 1.0 |
References
- http://secunia.com/advisories/22732Vendor Advisory
- http://secunia.com/advisories/22744Vendor Advisory
- http://secunia.com/advisories/22752PatchVendor Advisory
- http://secunia.com/advisories/22932
- http://secunia.com/advisories/23441
- http://security.gentoo.org/glsa/glsa-200612-20.xml
- http://www.discontinuity.info/~rowan/pocs/libimlib2_pocs-1.2.0-2.2.tar.gz
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:198
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:156
- http://www.novell.com/linux/security/advisories/2006_26_sr.html
- http://www.osvdb.org/30105
- http://www.osvdb.org/30106
- http://www.osvdb.org/30107
- http://www.osvdb.org/30108
- http://www.osvdb.org/30109
FAQ
What is CVE-2006-4806?
CVE-2006-4806 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (load...
How severe is CVE-2006-4806?
CVE-2006-4806 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4806?
Check the references section above for vendor advisories and patch information. Affected products include: Enlightenment Imlib2.