Vulnerability Description
Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcl Tk | Tcl Tk | <= 8.4.17 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
- http://secunia.com/advisories/28784PatchVendor Advisory
- http://secunia.com/advisories/28807Vendor Advisory
- http://secunia.com/advisories/28848Vendor Advisory
- http://secunia.com/advisories/28857Vendor Advisory
- http://secunia.com/advisories/28867Vendor Advisory
- http://secunia.com/advisories/28954Vendor Advisory
- http://secunia.com/advisories/29069Vendor Advisory
- http://secunia.com/advisories/29070Vendor Advisory
- http://secunia.com/advisories/29622Vendor Advisory
- http://secunia.com/advisories/30129Vendor Advisory
- http://secunia.com/advisories/30188Vendor Advisory
- http://secunia.com/advisories/30535Vendor Advisory
- http://secunia.com/advisories/30717Vendor Advisory
- http://secunia.com/advisories/30783Vendor Advisory
FAQ
What is CVE-2008-0553?
CVE-2008-0553 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4...
How severe is CVE-2008-0553?
CVE-2008-0553 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0553?
Check the references section above for vendor advisories and patch information. Affected products include: Tcl Tk Tcl Tk.