First published: Fri Sep 28 2007(Updated: )
Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tcl Tk | =8.4.13 | |
Tcl Tk | =8.4.14 | |
Tcl Tk | =8.4.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5137 has a high severity level due to its ability to allow remote code execution.
To fix CVE-2007-5137, you should update Tcl/Tk to a version after 8.4.15.
CVE-2007-5137 affects Tcl/Tk versions 8.4.13 to 8.4.15.
Yes, CVE-2007-5137 can be exploited remotely via specially crafted multi-frame interlaced GIF files.
CVE-2007-5137 is classified as a buffer overflow vulnerability.