CVE-2007-5137: Buffer Overflow
Published Sep 28, 2007
·Updated
Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378.
Affected Software
3 affected components
Tcl Tk Tcl Tk=8.4.13
Tcl Tk Tcl Tk=8.4.14
Tcl Tk Tcl Tk=8.4.15
Remediation
Patch Available
Event History
Sep 28, 2007
CVE Published
09:17 PM
Sep 29, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5137?
CVE-2007-5137 has a high severity level due to its ability to allow remote code execution.
2
How do I fix CVE-2007-5137?
To fix CVE-2007-5137, you should update Tcl/Tk to a version after 8.4.15.
3
What software is affected by CVE-2007-5137?
CVE-2007-5137 affects Tcl/Tk versions 8.4.13 to 8.4.15.
4
Can CVE-2007-5137 be exploited remotely?
Yes, CVE-2007-5137 can be exploited remotely via specially crafted multi-frame interlaced GIF files.
5
What type of vulnerability is CVE-2007-5137?
CVE-2007-5137 is classified as a buffer overflow vulnerability.