New User, Welcome!     Login

Next Page >>

image file

EEYE: Multiple Vulnerabilities In .FLAC File Format and Various Media Applications

Vulnerability #9: Picture Data Length Heap Overflow
By modifying the Picture Data Length field to an excessively large
value, such as 0xFFFFFFFF, a heap based overflow can be achieved. When a
vulnerable application that supports Picture Metadata blocks processes
an album art image, it uses this field to determine the size in bytes of
the embedded image file. This memory is allocated without bounds
checking and could be used to overwrite memory and pointers with
arbitrary values from inside the FLAC file.

Vulnerability #10: Picture URL Stack Overflow
Whenever a FLAC file's MIME-Type is set to "-->" this is a flag to

Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability

    Copyright (c) 2008 by Cisco Systems, Inc.
    
    ROM: System Bootstrap, Version 1.49(20080319:195807) [CRS-1 ROMMON],
    
    CRS uptime is 4 weeks, 4 days, 1 minute
    System image file is "disk0:hfr-os-mbi-3.6.2/mbihfr-rp.vm"
    
    cisco CRS-8/S (7457) processor with 4194304K bytes of memory.
    7457 processor at 1197Mhz, Revision 1.2
    
    17 Packet over SONET/SDH network interface(s)

[ MDVSA-2009:121-1 ] lcms

 Multiple security vulnerabilities has been identified and fixed in
 Little cms:
 
 A memory leak flaw allows remote attackers to cause a denial of service
 (memory consumption and application crash) via a crafted image file
 (CVE-2009-0581).
 
 Multiple integer overflows allow remote attackers to execute arbitrary
 code via a crafted image file that triggers a heap-based buffer
 overflow (CVE-2009-0723).

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

    http://www.gnu.org/licenses/gpl.html.
    
    Software
      loader:    Version 0.95
      system:    Version A3(1.0) [build 3.0(0)A3(0.0.148)]
      system image file: (nd)/192.168.65.31/scimitar.bin
    
      Device Manager version 1.1 (0) 20080805:0415
    
    ...
    <output truncated>

[ MDVSA-2009:162 ] java-1.6.0-openjdk

 Multiple security vulnerabilities has been identified and fixed in
 Little cms library embedded in OpenJDK:
 
 A memory leak flaw allows remote attackers to cause a denial of service
 (memory consumption and application crash) via a crafted image file
 (CVE-2009-0581).
 
 Multiple integer overflows allow remote attackers to execute arbitrary
 code via a crafted image file that triggers a heap-based buffer
 overflow (CVE-2009-0723).

Secunia Research: ACDSee Products Image and Archive Plug-ins Buffer Overflows

Secunia Research has discovered some vulnerabilities in ACDSee 
products, which can be exploited by malicious people to compromise a 
user's system.

1) An input validation error within ID_PSP.apl when processing PSP 
image files can be exploited to cause a heap-based buffer overflow via 
a specially crafted PSP image file.

2) An integer overflow error within ID_PSP.apl when processing PSP 
image files can be exploited to cause a heap-based buffer overflow via 
a specially crafted PSP image file.

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

    http://www.gnu.org/licenses/gpl.html

    Software
      loader:    Version 0.95
      system:    Version A3(1.0) [build 3.0(0)A3(0.0.148) adbuild_03:31:25-2008/08/06_/auto/adbure_nightly2/nightly_rel_a3_1_0_throttle/REL_3_0_0_A3_0_0
      system image file: (nd)/192.168.65.31/scimitar.bin

      Device Manager version 1.1 (0) 20080805:0415

    ...
    <output truncated>

[SECURITY] [DSA 1858-1] New imagemagick packages fix several vulnerabilities

   code via a crafted DCM image, or the colors or comments field in a 
   crafted XWD image. It only affects the oldstable distribution (etch).

CVE-2007-4985

   A crafted image file can trigger an infinite loop in the ReadDCMImage
   function or in the ReadXCFImage function. It only affects the oldstable
   distribution (etch).

CVE-2007-4986


[ GLSA 200806-03 ] Imlib 2: User-assisted execution of arbitrary code

Stefan Cornelius (Secunia Research) reported two boundary errors in
Imlib2:

* One of them within the load() function in the file
  src/modules/loaders/loader_pnm.c when processing the header of a PNM
  image file, possibly leading to a stack-based buffer overflow.

* The second one within the load() function in the file
  src/modules/loader_xpm.c when processing an XPM image file, possibly
  leading to a stack-based buffer overflow.


[USN-831-1] OpenEXR vulnerabilities

necessary changes.

Details follow:

Drew Yao discovered several flaws in the way OpenEXR handled certain
malformed EXR image files. If a user were tricked into opening a crafted
EXR image file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1720, CVE-2009-1721)

It was discovered that OpenEXR did not properly handle certain malformed

[HISPASEC] Fileinfo 2.0.9 plugin for Total Commander multiple vulnerabilities

raises an Access Violation exception, which causes DoS condition.

3. In a PE file, the IMAGE_OPTIONAL_HEADER contains an array of
IMAGE_DATA_DIRECTORY structures called DataDirectory. This structure
contains, above other, the size of the import directory. Fileinfo
fails to check this field in the Image File Header tab, which may
lead to printing out information about false DLL files, that in
reality are not loaded and not used.

4. In a PE file, the IMAGE_IMPORT_DESCRIPTOR contains pointers to
arrays of pointer to strings, and a pointer to a name of the DLL being

Secunia Research: e107 Avatar/Photograph Image File Upload Vulnerability

====================================================================== 

                     Secunia Research 19/04/2010

     - e107 Avatar/Photograph Image File Upload Vulnerability -

====================================================================== 
Table of Contents

Affected Software....................................................1

[ MDVSA-2008:005 ] - Updated libexif packages fix multiple vulnerabilities

 _______________________________________________________________________
 
 Problem Description:
 
 An infinite recursion flaw was found in the way that libexif parses
 Exif image tags.  A carefully crafted Exif image file opened by an
 application linked against libexif could cause the application to crash
 (CVE-2007-6351).
 
 An integer overflow flaw was also found in how libexif parses
 Exif image tags.  A carefully crafted Exif image file opened by

Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability

    Copyright (c) 2008 by Cisco Systems, Inc.
    
    ROM: System Bootstrap, Version 1.49(20080319:195807) [CRS-1 ROMMON],
    
    CRS uptime is 4 weeks, 4 days, 1 minute
    System image file is "disk0:hfr-os-mbi-3.6.2/mbihfr-rp.vm"
    
    cisco CRS-8/S (7457) processor with 4194304K bytes of memory.
    7457 processor at 1197Mhz, Revision 1.2
    
    17 Packet over SONET/SDH network interface(s)

[ MDVSA-2009:317 ] netpbm

 Multiple security vulnerabilities has been identified and fixed
 in netpbm:
 
 Multiple integer overflows in JasPer 1.900.1 might allow
 context-dependent attackers to have an unknown impact via a crafted
 image file, related to integer multiplication for memory allocation
 (CVE-2008-3520).
 
 Buffer overflow in the jas_stream_printf function in
 libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
 context-dependent attackers to have an unknown impact via

Cisco Security Advisory: Cisco IOS XR Software SSHv1 Denial of Service Vulnerability

    Copyright (c) 2008 by Cisco Systems, Inc.
    
    ROM: System Bootstrap, Version 1.49(20080319:195807) [CRS-1 ROMMON],
    
    CRS uptime is 4 weeks, 4 days, 1 minute
    System image file is "disk0:hfr-os-mbi-3.6.2/mbihfr-rp.vm"
    
    cisco CRS-8/S (7457) processor with 4194304K bytes of memory.
    7457 processor at 1197Mhz, Revision 1.2
    
    17 Packet over SONET/SDH network interface(s)

iDefense Security Advisory 12.09.08: Microsoft Windows Graphics Device Interface Integer Overflow Vulnerability

user.

This vulnerability exists in the way GDI handles integer math. An
integer overflow could occur while calculating the a buffer length,
which results in an undersized heap buffer being allocated. This buffer
is then overflowed with data from the input image file.

III. ANALYSIS

Exploitation allows an attacker to execute arbitrary code with the
privileges of the current user. Exploitation would require convincing a

[ MDVSA-2009:137 ] java-1.6.0-openjdk

 Multiple security vulnerabilities has been identified and fixed in
 Little cms library embedded in OpenJDK:
 
 A memory leak flaw allows remote attackers to cause a denial of service
 (memory consumption and application crash) via a crafted image file
 (CVE-2009-0581).
 
 Multiple integer overflows allow remote attackers to execute arbitrary
 code via a crafted image file that triggers a heap-based buffer
 overflow (CVE-2009-0723).

[ MDVSA-2009:121 ] lcms

 Multiple security vulnerabilities has been identified and fixed in
 Little cms:
 
 A memory leak flaw allows remote attackers to cause a denial of service
 (memory consumption and application crash) via a crafted image file
 (CVE-2009-0581).
 
 Multiple integer overflows allow remote attackers to execute arbitrary
 code via a crafted image file that triggers a heap-based buffer
 overflow (CVE-2009-0723).

[ MDVSA-2011:052 ] php

 (CVE-2011-0421).
 
 exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms
 performs an incorrect cast, which allows remote attackers to cause a
 denial of service (application crash) via an image with a crafted Image
 File Directory (IFD) that triggers a buffer over-read (CVE-2011-0708).
 
 Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows
 context-dependent attackers to cause a denial of service (crash)
 and possibly read sensitive memory via a large third argument to the
 shmop_read function (CVE-2011-1092).

[SECURITY] [DSA 2210-1] tiff security update

CVE-2011-0192

  A buffer overflow allows to execute arbitrary code or cause
  a denial of service via a crafted TIFF Internet Fax image
  file that has been compressed using CCITT Group 4 encoding.

CVE-2011-1167

  Heap-based buffer overflow in the thunder (aka ThunderScan)
  decoder allows to execute arbitrary code via a TIFF file that

[SECURITY] [DSA 1819-1] New vlc packages fix several vulnerabilities

when opening a crafted .ty file.

CVE-2008-5032

Tobias Klein discovered that it is possible to execute arbitrary code
when opening an invalid CUE image file with a crafted header.


For the oldstable distribution (etch), these problems have been fixed
in version 0.8.6-svn20061012.debian-5.1+etch3.


Cisco Security Advisory: Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities

    http://www.gnu.org/licenses/gpl.html.

    Software
      loader:    Version 0.95
      system:    Version A3(2.1) [build 3.0(0)A3(2.1) adbuild_14:33:29-2008/11/19_/auto/adbu-rel4/rel_a3_2_1_throttle_build/REL_3_0_0_A3_2_1]
      system image file: (nd)/192.168.65.32/scimitar.bin
      Device Manager version 1.1 (0) 20081113:2052
    ---

Determining ANM Software Version
+-------------------------------

[ MDVSA-2008:099 ] - Updated ImageMagick packages fix vulnerabilities

 of its allocated memory, potentially allowing an attacker to execute
 arbitrary code on the system running ImageMagick (CVE-2008-1096).
 
 Another heap-based buffer overflow vulnerability was found in how
 ImageMagick processed certain malformed PCX images.  If ImageMagick
 opened a specially-crafted PCX image file, an attacker could
 possibly execute arbitrary code on the system running ImageMagick
 (CVE-2008-1097).
 
 The updated packages have been patched to correct these issues.
 _______________________________________________________________________

[USN-707-1] CUPS vulnerabilities

restrictions and add a large number of RSS subscriptions. This issue only
applied to Ubuntu 7.10 and 8.04 LTS. (CVE-2008-5184)

It was discovered that the PNG filter in CUPS did not properly handle certain
malformed images. If a user or automated system were tricked into opening a
crafted PNG image file, a remote attacker could cause a denial of service or
execute arbitrary code with user privileges. In Ubuntu 7.10, 8.04 LTS, and 8.10,
attackers would be isolated by the AppArmor CUPS profile. (CVE-2008-5286)

It was discovered that the example pstopdf CUPS filter created log files in an
insecure way. Local users could exploit a race condition to create or overwrite

[ MDVSA-2011:053 ] php

 (CVE-2011-0421).
 
 exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms
 performs an incorrect cast, which allows remote attackers to cause a
 denial of service (application crash) via an image with a crafted Image
 File Directory (IFD) that triggers a buffer over-read (CVE-2011-0708).
 
 Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows
 context-dependent attackers to cause a denial of service (crash)
 and possibly read sensitive memory via a large third argument to the
 shmop_read function (CVE-2011-1092).

[oCERT-2009-003] LittleCMS integer errors

Description:

LittleCMS, an open source color management engine, suffers from several
integer errors, resulting in stack based buffer overflows and various heap
errors as well as dangerous memory leaks. Decoding a specially crafted
image file will result in unexpected process termination, Denial Of
Service conditions or arbitrary code execution due to stack overflow.

LittleCMS is used by several Open Source projects including OpenJDK,
Firefox and GIMP.


Stack overflow in Microsoft HTML Help 6.1 (CHM files)

The provided chm_1.chm proof-of-concept contains the address where will
continue the code execution at offset 0x17 of test.gif (set to
0x41414141, you can use any value because it's binary data) and I have
placed a bindshell (w32-bind-ngs-shellcode by SkyLined) at offset 0x200
of the same image file only as reference during my tests.

The folder build_chm_1 instead contains the original files from which
has been created chm_1.chm using the steps listed above.



Lomtec ActiveWeb Professional 3.0 CMS Allows Arbitrary File Upload and Execution as SYSTEM in ColdFusion (2010-WEB-002) (CERT VU#528212)

SUMMARY AND IMPACT:
The ActiveWeb Professional 3.0 web content management server is
vulnerable to remote operating system takeover. An unauthenticated
remote user can upload malicious files and backdoor ColdFusion
websites using the EasyEdit.cfm page. By accessing the "getImagefile"
section of the EasyEdit module, the remote attacker can change hidden
form fields to upload malicious applications and ColdFusion CFML
websites that execute those malicious applications or operating system
commands in the context of the ColdFusion service account (SYSTEM).
The remote user can now perform all functions of the system

TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability

TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption  
Vulnerability
http://www.zerodayinitiative.com/advisories/TPTI-08-01.html
January 15, 2008

-- CVE ID:
CVE-2008-0033

-- Affected Vendor:
Apple

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!