Cairo PNG Image Processing Remote Integer Overflow Vulnerability
BID:26650
Info
Cairo PNG Image Processing Remote Integer Overflow Vulnerability
| Bugtraq ID: | 26650 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5503 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2007 12:00AM |
| Updated: | Mar 19 2015 09:43AM |
| Credit: | Peter Valchev found this vulnerability. |
| Vulnerable: |
VMWare Workstation 6.0.5 build 109488 VMWare Workstation 6.0.5 VMWare Player 2.0.5 build 109488 VMWare Player 2.0.5 VMWare Fusion 1.1.2 VMWare Fusion 1.1.1 VMWare Fusion 1.1 VMWare Fusion 1.1.2 build 87978 VMWare Fusion 1.0 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE openSUSE 10.3 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Cairo Cairo 1.4.10 Cairo Cairo 1.4.2 Cairo Cairo 1.2.4 Cairo Cairo 1.0.4 |
| Not Vulnerable: |
Cairo Cairo 1.4.12 |
Discussion
Cairo PNG Image Processing Remote Integer Overflow Vulnerability
Cairo is prone to an integer-overflow vulnerability because it fails to ensure that integer values aren't overrun. Attackers may exploit this issue to overflow a buffer and to corrupt process memory.
Attackers may be able to execute arbitrary machine code in the context of an affected application. Failed exploit attempts will likely result in a denial-of-service condition.
This issue affects versions prior to Cairo 1.4.12.
Cairo is prone to an integer-overflow vulnerability because it fails to ensure that integer values aren't overrun. Attackers may exploit this issue to overflow a buffer and to corrupt process memory.
Attackers may be able to execute arbitrary machine code in the context of an affected application. Failed exploit attempts will likely result in a denial-of-service condition.
This issue affects versions prior to Cairo 1.4.12.
Exploit / POC
Cairo PNG Image Processing Remote Integer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cairo PNG Image Processing Remote Integer Overflow Vulnerability
Solution:
The vendor has released Cario 1.4.12 to address this issue.
Cairo Cairo 1.4.10
Solution:
The vendor has released Cario 1.4.12 to address this issue.
Cairo Cairo 1.4.10
-
Cairo Cairo 14.12
http://cairographics.org/download/
References
Cairo PNG Image Processing Remote Integer Overflow Vulnerability
References:
References:
- Bugzilla Bug 387431: CVE-2007-5503 cairo integer overflow (Josh Bressers)
- cairo 1.4.12 release available (Cairo)
- Home Page (Cairo)
- RHSA-2007:1078-3 - cairo security update (RedHat)