ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
BID:11556
Info
ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
| Bugtraq ID: | 11556 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0994 CVE-2004-1095 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of these issues is credited to Sean <[email protected]> and Luke Macken. |
| Vulnerable: |
zgv Image Viewer 5.8 zgv Image Viewer 5.7 zgv Image Viewer 5.6 zgv Image Viewer 5.5 xzgv Image Viewer 0.8 xzgv Image Viewer 0.7 xzgv Image Viewer 0.6 Gentoo Linux Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha |
| Not Vulnerable: | |
Discussion
ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
zgv is reportedly affected by multiple remote integer overflow vulnerabilities. These issues are due to a failure of the application to perform adequate sanity checking on image values prior to copying image data into process buffers.
An attacker may leverage these issues to execute arbitrary code on an affected computer with the privileges of the user running the vulnerable application.
zgv is reportedly affected by multiple remote integer overflow vulnerabilities. These issues are due to a failure of the application to perform adequate sanity checking on image values prior to copying image data into process buffers.
An attacker may leverage these issues to execute arbitrary code on an affected computer with the privileges of the user running the vulnerable application.
Exploit / POC
ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
Solution:
Debian linux has released advisory DSA 614-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200411-12:01 to address this issue in zgv. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/zgv-5.8"
The vendor has released patches dealing with this issue in both the zgv and xzgv applications.
Debian linux has released advisory DSA 608-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA GLSA 200501-09 to address this issue in xzgv. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/xzgv-0.8-r1"
xzgv Image Viewer 0.7
xzgv Image Viewer 0.8
zgv Image Viewer 5.5
zgv Image Viewer 5.8
Solution:
Debian linux has released advisory DSA 614-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200411-12:01 to address this issue in zgv. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/zgv-5.8"
The vendor has released patches dealing with this issue in both the zgv and xzgv applications.
Debian linux has released advisory DSA 608-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA GLSA 200501-09 to address this issue in xzgv. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/xzgv-0.8-r1"
xzgv Image Viewer 0.7
-
Debian xzgv_0.7-6woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_a lpha.deb -
Debian xzgv_0.7-6woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_a rm.deb -
Debian xzgv_0.7-6woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_h ppa.deb -
Debian xzgv_0.7-6woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_i 386.deb -
Debian xzgv_0.7-6woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_i a64.deb -
Debian xzgv_0.7-6woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_m 68k.deb -
Debian xzgv_0.7-6woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_m ips.deb -
Debian xzgv_0.7-6woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_m ipsel.deb -
Debian xzgv_0.7-6woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_p owerpc.deb -
Debian xzgv_0.7-6woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_s 390.deb -
Debian xzgv_0.7-6woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody2_s parc.deb
xzgv Image Viewer 0.8
-
xzgv xzgv-0.8-integer-overflow-fix.diff
http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff
zgv Image Viewer 5.5
-
Debian zgv_5.5-3woody2_i386.deb
http://security.debian.org/pool/updates/main/z/zgv/zgv_5.5-3woody2_i38 6.deb
zgv Image Viewer 5.8
-
zgv zgv-5.8-integer-overflow-fix.diff
http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff
References
ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities
References:
References:
- xzgv Image Viewer Home Page (xzgv)
- zgv Home Page (zgv)
- iDEFENSE SecurityAdvisory12.13.04-xzgvPRF Parsing Integer Overflow Vulnerability ("customer service mailbox"
) - Re: zgv image viewing heap overflows (Sean
) - zgv image viewing heap overflows (Sean
)