New User, Welcome!     Login

Next Page >>

Heap/based

[ MDVSA-2009:319 ] xine-lib

 
 Failure on manipulation of either MNG or Real or MOD files can lead
 remote attackers to cause a denial of service by using crafted files
 (CVE: CVE-2008-5233).
 
 Heap-based overflow allows remote attackers to execute arbitrary
 code by using Quicktime media files holding crafted metadata
 (CVE-2008-5234).
 
 Heap-based overflow allows remote attackers to execute arbitrary code
 by using either crafted Matroska or Real media files (CVE-2008-5236).

[ MDVSA-2010:055 ] poppler

 (application crash) via a crafted PDF document (CVE-2009-1188).
 
 Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x
 before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers
 to execute arbitrary code via a crafted PDF document that triggers a
 heap-based buffer overflow.  NOTE: some of these details are obtained
 from third party information.  NOTE: this issue reportedly exists
 because of an incomplete fix for CVE-2009-1188 (CVE-2009-3603).
 
 The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x
 before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF,

[ MDVSA-2009:020 ] xine-lib

 
 Failure on manipulation of either MNG or Real or MOD files can lead
 remote attackers to cause a denial of service by using crafted files
 (CVE: CVE-2008-5233).
 
 Heap-based overflow allows remote attackers to execute arbitrary
 code by using Quicktime media files holding crafted metadata
 (CVE-2008-5234).
 
 Heap-based overflow allows remote attackers to execute arbitrary code
 by using either crafted Matroska or Real media files (CVE-2008-5236).

[USN-710-1] xine-lib vulnerabilities

could crash xine-lib or possibly execute arbitrary code with the privileges of
the user invoking the program. This issue only applied to Ubuntu 6.06 LTS, 7.10,
and 8.04 LTS. (CVE-2008-5233)

It was discovered that the QT demuxer in xine-lib did not correctly handle
an invalid metadata atom size, resulting in a heap-based buffer overflow. If a
user or automated system were tricked into opening a specially crafted MOV file,
an attacker could execute arbitrary code as the user invoking the program.
(CVE-2008-5234, CVE-2008-5242)

It was discovered that the Real, RealAudio, and Matroska demuxers in xine-lib

[ MDVSA-2011:175 ] poppler

 (application crash) via a crafted PDF document (CVE-2009-1188).
 
 Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x
 before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers
 to execute arbitrary code via a crafted PDF document that triggers a
 heap-based buffer overflow.  NOTE: some of these details are obtained
 from third party information.  NOTE: this issue reportedly exists
 because of an incomplete fix for CVE-2009-1188 (CVE-2009-3603).
 
 The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x
 before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF,

[ MDVSA-2009:287-1 ] xpdf

 Multiple vulnerabilities has been found and corrected in xpdf:
 
 Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x
 before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers
 to execute arbitrary code via a crafted PDF document that triggers a
 heap-based buffer overflow.  NOTE: some of these details are obtained
 from third party information.  NOTE: this issue reportedly exists
 because of an incomplete fix for CVE-2009-1188 (CVE-2009-3603).
 
 The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x
 before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF,

[ MDVSA-2010:105 ] openoffice.org

 This updates provides a new OpenOffice.org version 3.1.1. It holds
 security and bug fixes described as follow:
 
 An integer underflow might allow remote attackers to execute arbitrary
 code via crafted records in the document table of a Word document,
 leading to a heap-based buffer overflow (CVE-2009-0200).
 
 A heap-based buffer overflow might allow remote attackers to execute
 arbitrary code via unspecified records in a crafted Word document,
 related to table parsing (CVE-2009-0201).
 

[ MDVSA-2010:087 ] poppler

 
 The JBIG2 decoder in Xpdf 3.02pl2 and earlier allows remote attackers
 to cause a denial of service (crash) via a crafted PDF file that
 triggers a free of uninitialized memory (CVE-2009-0166).
 
 Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9,
 and probably other products, allows remote attackers to execute
 arbitrary code via a PDF file with crafted JBIG2 symbol dictionary
 segments (CVE-2009-0195).
 
 The JBIG2 decoder in Xpdf 3.02pl2 and earlier allows remote attackers

[ MDVSA-2010:091 ] openoffice.org

 This updates provides a new OpenOffice.org version 3.1.1. It holds
 security and bug fixes described as follow:
 
 An integer underflow might allow remote attackers to execute arbitrary
 code via crafted records in the document table of a Word document,
 leading to a heap-based buffer overflow (CVE-2009-0200).
 
 A heap-based buffer overflow might allow remote attackers to execute
 arbitrary code via unspecified records in a crafted Word document,
 related to table parsing (CVE-2009-0201).
 

[ MDVSA-2010:035 ] openoffice.org

 This updates provides a new OpenOffice.org version 3.1.1. It holds
 security and bug fixes described as follow:
 
 An integer underflow might allow remote attackers to execute arbitrary
 code via crafted records in the document table of a Word document,
 leading to a heap-based buffer overflow (CVE-2009-0200).
 
 A heap-based buffer overflow might allow remote attackers to execute
 arbitrary code via unspecified records in a crafted Word document,
 related to table parsing (CVE-2009-0201).
 

[SECURITY] [DSA 1903-1] New graphicsmagick packages fix several vulnerabilities

CVE-2007-4986

  Multiple integer overflows allow context-dependent attackers to execute
  arbitrary code via a crafted .dcm, .dib, .xbm, .xcf, or .xwd image file,
  which triggers a heap-based buffer overflow. It only affects the
  oldstable distribution (etch).

CVE-2007-4988

  A sign extension error allows context-dependent attackers to execute

[ MDVSA-2009:287 ] xpdf

 Multiple vulnerabilities has been found and corrected in xpdf:
 
 Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x
 before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers
 to execute arbitrary code via a crafted PDF document that triggers a
 heap-based buffer overflow.  NOTE: some of these details are obtained
 from third party information.  NOTE: this issue reportedly exists
 because of an incomplete fix for CVE-2009-1188 (CVE-2009-3603).
 
 The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x
 before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF,

[ GLSA 200907-06 ] Adobe Reader: User-assisted execution of arbitrary code

Description
===========

Multiple vulnerabilities have been reported in Adobe Reader:

* Alin Rad Pop of Secunia Research reported a heap-based buffer
  overflow in the JBIG2 filter (CVE-2009-0198).

* Mark Dowd of the IBM Internet Security Systems X-Force and Nicolas
  Joly of VUPEN Security reported multiple heap-based buffer overflows
  in the JBIG2 filter (CVE-2009-0509, CVE-2009-0510, CVE-2009-0511,

CORE-2009-0122: HP OpenView Buffer Overflows

Manager, which can be exploited to remotely compromise a user's system.

While working on an exploit for the vulnerabilities disclosed in the
advisory [3], three bugs were found. The stack-based bug found on CGI
parameter 'OvOSLocale' is similar to one of the bugs previously reported
in [3] whereas the two heap-based bugs are different vulnerabilities.

Versions 7.51, 7.53, and 7.53 with patch NNM_01195 were tested and all
of them were vulnerable. The two heap-based buffer overflows are
different vulnerabilities from those exposed publicly on CVE-2008-0067
because the vulnerabilities are not fixed with patch NNM_01195 and are

iDefense Security Advisory 11.03.08: Multiple Vendor CUPS SGI imagetops Heap Overflow Vulnerability

http://www.cups.org/

II. DESCRIPTION

Remote exploitation of a heap-based buffer overflow vulnerability in
CUPS, as included in various vendors' operating system distributions,
could allow an attacker to execute arbitrary code with the privileges
of the affected service.

The Common Unix Printing System, more commonly referred to as CUPS,

[ MDVSA-2008:162 ] qemu

 Problem Description:

 Multiple vulnerabilities have been found in Qemu.
 
 Multiple heap-based buffer overflows in the cirrus_invalidate_region
 function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and
 possibly other products, might allow local users to execute arbitrary
 code via unspecified vectors related to attempting to mark non-existent
 regions as dirty, aka the bitblt heap overflow. (CVE-2007-1320)
 

Secunia Research: Lotus Notes EML Reader Buffer Overflows

user's system.

1) A boundary error in the EML reader (emlsr.dll) when parsing certain
headers ("To:", "Cc:", "Bcc:", "From:", "Date:", "Subject:",
"Priority:", "Importance:", and "X-MSMail-Priority:") in EML files can
be exploited to cause a heap-based buffer overflow via an overly long
string.

2) A boundary error in the EML reader (emlsr.dll) when encountering the
beginning of RFC2047 encoded-words in headers can be exploited to cause
a heap-based buffer overflow via an overly long string.

Secunia Research: Autonomy Keyview EML Reader Buffer Overflows

user's system.

1) A boundary error in the EML reader (emlsr.dll) when parsing certain
headers ("To:", "Cc:", "Bcc:", "From:", "Date:", "Subject:",
"Priority:", "Importance:", and "X-MSMail-Priority:") in EML files can
be exploited to cause a heap-based buffer overflow via an overly long
string.

2) A boundary error in the EML reader (emlsr.dll) when encountering the
beginning of RFC2047 encoded-words in headers can be exploited to cause
a heap-based buffer overflow via an overly long string.

[ MDVSA-2010:221 ] openoffice.org

 Multiple vulnerabilities was discovered and corrected in the
 OpenOffice.org:
 
 Integer overflow allows remote attackers to execute arbitrary code
 via a crafted XPM file that triggers a heap-based buffer overflow
 (CVE-2009-2949).
 
 Heap-based buffer overflow allows remote attackers to cause a denial
 of service (application crash) or possibly execute arbitrary code
 via a crafted GIF file, related to LZW decompression (CVE-2009-2950).

[ MDVSA-2010:096 ] tetex

 
 The JBIG2 decoder in Xpdf 3.02pl2 and earlier allows remote attackers
 to cause a denial of service (crash) via a crafted PDF file that
 triggers a free of uninitialized memory (CVE-2009-0166).
 
 Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9,
 and probably other products, allows remote attackers to execute
 arbitrary code via a PDF file with crafted JBIG2 symbol dictionary
 segments (CVE-2009-0195).
 
 Buffer overflow in BibTeX 0.99 allows context-dependent attackers to

[ MDVSA-2009:282-1 ] cups

 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon
 crash) and possibly execute arbitrary code via a crafted TIFF image,
 which is not properly handled by the (1) _cupsImageReadTIFF function
 in the imagetops filter and (2) imagetoraster filter, leading to a
 heap-based buffer overflow. (CVE-2009-0163)
 
 Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier,
 as used in Poppler and other products, when running on Mac OS X,
 has unspecified impact, related to g*allocn. (CVE-2009-0165)
 

[ MDVSA-2010:056 ] openoffice.org

 This update provides the OpenOffice.org 3.0 major version and holds
 the security fixes for the following issues:
 
 An integer underflow might allow remote attackers to execute arbitrary
 code via crafted records in the document table of a Word document
 leading to a heap-based buffer overflow (CVE-2009-0200).
 
 An heap-based buffer overflow might allow remote attackers to execute
 arbitrary code via unspecified records in a crafted Word document
 related to table parsing. (CVE-2009-0201).
 

[ MDVSA-2009:283 ] cups

 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon
 crash) and possibly execute arbitrary code via a crafted TIFF image,
 which is not properly handled by the (1) _cupsImageReadTIFF function
 in the imagetops filter and (2) imagetoraster filter, leading to a
 heap-based buffer overflow. (CVE-2009-0163)
 
 The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier,
 and other products allows remote attackers to cause a denial of service
 (crash) via a crafted PDF file that triggers a free of uninitialized
 memory. (CVE-2009-0166)

[CORE-2009-1126] Corel Paint Shop Pro Photo X2 FPX Heap Overflow

2. *Vulnerability Information*

Class: Heap-based Buffer Overflow [CWE-119]
Impact: Code execution
Remotely Exploitable: Yes (client-side)
Locally Exploitable: No
Bugtraq ID: 37980
CVE Name: N/A

[ MDVSA-2009:282 ] cups

 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon
 crash) and possibly execute arbitrary code via a crafted TIFF image,
 which is not properly handled by the (1) _cupsImageReadTIFF function
 in the imagetops filter and (2) imagetoraster filter, leading to a
 heap-based buffer overflow. (CVE-2009-0163)
 
 Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier,
 as used in Poppler and other products, when running on Mac OS X,
 has unspecified impact, related to g*allocn. (CVE-2009-0165)
 

[ MDVSA-2009:311 ] ghostscript

 remote attackers to cause a denial of service and possibly to execute
 arbitrary code via a crafted Postscript file (CVE-2008-6679).
 
 Multiple interger overflows in Ghostsript's International Color
 Consortium Format Library (icclib) allows attackers to cause denial
 of service (heap-based buffer overflow and application crash) and
 possibly execute arbirary code by using either a PostScript or PDF
 file with crafte embedded images (CVE-2009-0583, CVE-2009-0584).
 
 Multiple interger overflows in Ghostsript's International Color
 Consortium Format Library (icclib) allows attackers to cause denial

[ MDVSA-2009:286 ] ocaml-camlimages

 Multiple vulnerabilities has been found and corrected in
 ocaml-camlimages:
 
 Multiple integer overflows in CamlImages 2.2 and earlier might allow
 context-dependent attackers to execute arbitrary code via a crafted
 PNG image with large width and height values that trigger a heap-based
 buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24
 function (CVE-2009-2295).
 
 Multiple integer overflows in CamlImages 2.2 might allow
 context-dependent attackers to execute arbitrary code via images

[SECURITY] [DSA 1858-1] New imagemagick packages fix several vulnerabilities

CVE-2007-4986

   Multiple integer overflows allow context-dependent attackers to execute
   arbitrary code via a crafted .dcm, .dib, .xbm, .xcf, or .xwd image file,
   which triggers a heap-based buffer overflow. It only affects the  
   oldstable distribution (etch).

CVE-2007-4987

   Off-by-one error allows context-dependent attackers to execute arbitrary

[SECURITY] [DSA 1814-1] New libsndfile packages fix arbitrary code execution

http://www.debian.org/security/                                 Nico Golde
June 13th, 2009                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : libsndfile
Vulnerability  : heap-based buffer overflow
Problem type   : local (remote)
Debian-specific: no
Debian bug     : 528650
CVE ID         : CVE-2009-1788 CVE-2009-1791


[ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple heap-based buffer overflow vulnerabilities in libsndfile might
allow remote attackers to execute arbitrary code.

Background
==========


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!