CVE-2008-2426: Buffer Overflow
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loaderpnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loaderxpm.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2426?
CVE-2008-2426 is classified as a critical vulnerability due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2008-2426?
To fix CVE-2008-2426, update Imlib 2 to a version later than 1.4.0 where this vulnerability has been addressed.
What types of files are affected by CVE-2008-2426?
CVE-2008-2426 specifically affects PNM image files with crafted headers.
Can CVE-2008-2426 be exploited remotely?
Yes, CVE-2008-2426 can be exploited remotely by attackers through specially crafted PNM images.
What is Imlib 2 in relation to CVE-2008-2426?
Imlib 2 is a graphic library for creating and manipulating images, and CVE-2008-2426 identifies vulnerabilities specific to version 1.4.0.