Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
BID:27655
Info
Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
| Bugtraq ID: | 27655 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0553 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2008 12:00AM |
| Updated: | Mar 19 2015 08:30AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.5 patch 6 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 Patch 17 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 TCL/TK TCL/TK 8.5 a3 TCL/TK TCL/TK 8.5 a2 TCL/TK TCL/TK 8.5 TCL/TK TCL/TK 8.4.16 TCL/TK TCL/TK 8.4.15 TCL/TK TCL/TK 8.4.14 TCL/TK TCL/TK 8.4.13 TCL/TK TCL/TK 8.4.12 TCL/TK TCL/TK 8.4.11 TCL/TK TCL/TK 8.4.10 TCL/TK TCL/TK 8.4.9 TCL/TK TCL/TK 8.4.8 TCL/TK TCL/TK 8.4.7 TCL/TK TCL/TK 8.4.6 TCL/TK TCL/TK 8.4.5 TCL/TK TCL/TK 8.4.4 TCL/TK TCL/TK 8.4.3 TCL/TK TCL/TK 8.4.2 TCL/TK TCL/TK 8.4.1 TCL/TK TCL/TK 8.4 TCL/TK TCL/TK 8.3.5 TCL/TK TCL/TK 8.3.4 TCL/TK TCL/TK 8.3.3 TCL/TK TCL/TK 8.3.2 TCL/TK TCL/TK 8.3.1 TCL/TK TCL/TK 8.3 TCL/TK TCL/TK 8.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE Linux Enterprise Server RT Solution 10 0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 5.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4.5.z RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora 9 Red Hat Fedora 8 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4.5.z Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Interactive Response 2.0 |
| Not Vulnerable: |
VMWare ESX Server 2.5.5 patch 8 VMWare ESX Server 2.5.4 patch 19 TCL/TK TCL/TK 8.5.1 |
Discussion
Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
TCL/TK Tk Toolkit is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied GIF image data before copying it to an insufficiently sized buffer.
Successful exploits may allow attackers to execute arbitrary code in the context of applications that use the affected toolkit. Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Tcl/Tk 8.5.1 are vulnerable to this issue.
TCL/TK Tk Toolkit is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied GIF image data before copying it to an insufficiently sized buffer.
Successful exploits may allow attackers to execute arbitrary code in the context of applications that use the affected toolkit. Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Tcl/Tk 8.5.1 are vulnerable to this issue.
Exploit / POC
Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
Solution:
The vendor addressed this issue in TCL/TK 8.5.1. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
TCL/TK TCL/TK 8.0
TCL/TK TCL/TK 8.3
TCL/TK TCL/TK 8.3.1
TCL/TK TCL/TK 8.3.3
TCL/TK TCL/TK 8.3.5
TCL/TK TCL/TK 8.4.1
TCL/TK TCL/TK 8.4.11
TCL/TK TCL/TK 8.4.15
TCL/TK TCL/TK 8.4.2
TCL/TK TCL/TK 8.4.4
TCL/TK TCL/TK 8.4.5
TCL/TK TCL/TK 8.4.6
TCL/TK TCL/TK 8.4.8
TCL/TK TCL/TK 8.4.9
TCL/TK TCL/TK 8.5 a2
Solution:
The vendor addressed this issue in TCL/TK 8.5.1. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu tk8.4-dev_8.4.16-2ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/t/tk8.4/tk8.4-dev_8.4.16-2ubuntu1.1_ lpia.deb -
Ubuntu tk8.4-doc_8.4.16-2ubuntu1.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.4/tk8.4-doc_8.4.16-2 ubuntu1.1_all.deb -
Ubuntu tk8.4_8.4.16-2ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/t/tk8.4/tk8.4_8.4.16-2ubuntu1.1_lpia .deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu tk8.0-dev_8.0.5-11ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/t/tk8.0/tk8.0-dev_8.0. 5-11ubuntu0.1_i386.deb -
Ubuntu tk8.0-doc_8.0.5-11ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/t/tk8.0/tk8.0-doc_8.0. 5-11ubuntu0.1_all.deb -
Ubuntu tk8.0_8.0.5-11ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.0/tk8.0_8.0.5-11ubun tu0.1_i386.deb -
Ubuntu tk8.3-dev_8.3.5-4ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.3/tk8.3-dev_8.3.5-4u buntu1.2_i386.deb -
Ubuntu tk8.3-doc_8.3.5-4ubuntu1.2_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/t/tk8.3/tk8.3-doc_8.3. 5-4ubuntu1.2_all.deb -
Ubuntu tk8.3_8.3.5-4ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.3/tk8.3_8.3.5-4ubunt u1.2_i386.deb -
Ubuntu tk8.4-dev_8.4.12-0ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.4/tk8.4-dev_8.4.12-0 ubuntu1.2_i386.deb -
Ubuntu tk8.4-doc_8.4.12-0ubuntu1.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.4/tk8.4-doc_8.4.12-0 ubuntu1.2_all.deb -
Ubuntu tk8.4_8.4.12-0ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tk8.4/tk8.4_8.4.12-0ubun tu1.2_i386.deb
TCL/TK TCL/TK 8.0
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.3
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.3.1
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.3.3
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.3.5
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.1
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.11
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.15
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.2
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.4
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.5
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.6
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.8
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.4.9
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
TCL/TK TCL/TK 8.5 a2
-
TCL/TK tk8.5.1-src.tar.gz
http://prdownloads.sourceforge.net/tcl/tk8.5.1-src.tar.gz
References
Tcl/Tk Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerability
References:
References:
- Release Name: 8.5.1 (TCL/TK)
- Tcl/Tk Home Page (Tcl/Tk)
- ASA-2008-215 Security Vulnerabilities in the Tcl GUI Toolkit Library may lead to (Avaya)
- RHSA-2008:0134-3 tcltk security update (Red Hat)
- RHSA-2008:0135-1 tk security update (Red Hat)
- RHSA-2008:0135-2 tk security update (Red Hat)
- RHSA-2008:0136-1 tk security update (Red Hat)
- Solution 237465 : Security Vulnerabilities in the Tcl GUI Toolkit Library may l (Sun)