Inkscape SVG Image Buffer Overflow Vulnerability
BID:15507
Info
Inkscape SVG Image Buffer Overflow Vulnerability
| Bugtraq ID: | 15507 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3737 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2005 12:00AM |
| Updated: | Nov 21 2005 12:00AM |
| Credit: | Joxean Koret is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 Inkscape Inkscape 0.42 Inkscape Inkscape 0.41 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Inkscape SVG Image Buffer Overflow Vulnerability
Inkscape is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before copying it into a finite sized buffer.
When the application processes a malformed SVG image file, it results in a buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the victim user.
Inkscape is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before copying it into a finite sized buffer.
When the application processes a malformed SVG image file, it results in a buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the victim user.
Exploit / POC
Inkscape SVG Image Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following denial of service proof of concept is available:
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following denial of service proof of concept is available:
Solution / Fix
Inkscape SVG Image Buffer Overflow Vulnerability
Solution:
Ubuntu Linux has released security advisory USN-217-1 addressing this issue. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200511-22 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/inkscape-0.43"
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
Debian has released advisory DSA 916-1 to address this issue. Please see the referenced advisory for more information.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Ubuntu Linux has released security advisory USN-217-1 addressing this issue. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200511-22 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/inkscape-0.43"
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
Debian has released advisory DSA 916-1 to address this issue. Please see the referenced advisory for more information.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Inkscape SVG Image Buffer Overflow Vulnerability
References:
References: