XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
BID:17409
Info
XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 17409 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-1060 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2006 12:00AM |
| Updated: | Dec 06 2006 06:44PM |
| Credit: | Reported by Dirk Mueller. |
| Vulnerable: |
zgv Image Viewer 5.9 zgv Image Viewer 5.8 zgv Image Viewer 5.7 zgv Image Viewer 5.6 zgv Image Viewer 5.5 xzgv Image Viewer 0.8 xzgv Image Viewer 0.7 xzgv Image Viewer 0.6 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
The 'xzgv' viewer is reported prone to a remote heap-overflow vulnerability.
This issue is reported to present itself when the application handles a specially crafted JPEG image. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue affects 'xzgv' 0.8 and prior. 'zgv' image viewer is vulnerable to this issue as well.
The 'xzgv' viewer is reported prone to a remote heap-overflow vulnerability.
This issue is reported to present itself when the application handles a specially crafted JPEG image. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue affects 'xzgv' 0.8 and prior. 'zgv' image viewer is vulnerable to this issue as well.
Exploit / POC
XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
Solution:
Gentoo has released an updated version of their advisory since the ebuild listed in the original advisory did not address all of the issues.
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
xzgv Image Viewer 0.7
xzgv Image Viewer 0.8
zgv Image Viewer 5.5
Solution:
Gentoo has released an updated version of their advisory since the ebuild listed in the original advisory did not address all of the issues.
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
xzgv Image Viewer 0.7
-
Debian xzgv_0.7-6woody3_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_a lpha.deb -
Debian xzgv_0.7-6woody3_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_a rm.deb -
Debian xzgv_0.7-6woody3_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_h ppa.deb -
Debian xzgv_0.7-6woody3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_i 386.deb -
Debian xzgv_0.7-6woody3_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_i a64.deb -
Debian xzgv_0.7-6woody3_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_m 68k.deb -
Debian xzgv_0.7-6woody3_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_m ips.deb -
Debian xzgv_0.7-6woody3_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_m ipsel.deb -
Debian xzgv_0.7-6woody3_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_p owerpc.deb -
Debian xzgv_0.7-6woody3_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_s 390.deb -
Debian xzgv_0.7-6woody3_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.7-6woody3_s parc.deb
xzgv Image Viewer 0.8
-
Debian xzgv_0.8-3sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_a lpha.deb -
Debian xzgv_0.8-3sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_a md64.deb -
Debian xzgv_0.8-3sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_a rm.deb -
Debian xzgv_0.8-3sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_h ppa.deb -
Debian xzgv_0.8-3sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_i 386.deb -
Debian xzgv_0.8-3sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_i a64.deb -
Debian xzgv_0.8-3sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_m 68k.deb -
Debian xzgv_0.8-3sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_m ips.deb -
Debian xzgv_0.8-3sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_m ipsel.deb -
Debian xzgv_0.8-3sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_p owerpc.deb -
Debian xzgv_0.8-3sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_s 390.deb -
Debian xzgv_0.8-3sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xzgv/xzgv_0.8-3sarge1_s parc.deb
zgv Image Viewer 5.5
-
Debian zgv_5.5-3woody3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zgv/zgv_5.5-3woody3_i38 6.deb
References
XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
References:
References:
- xzgv Image Viewer Home Page (xzgv)