First published: Thu Mar 06 2008(Updated: )
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actual height and width.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =m3-rc37a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0985 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2008-0985, users should update to the latest version of the Google Android SDK that resolves this buffer overflow issue.
CVE-2008-0985 is caused by a heap-based buffer overflow in the GIF library of the WebKit framework in specific versions of the Google Android SDK.
CVE-2008-0985 affects users of the Google Android SDK version m3-rc37a and earlier.
Yes, CVE-2008-0985 can be exploited remotely through a crafted GIF file.