Graphviz GIF File Remote Buffer Overflow Vulnerability
BID:27768
Info
Graphviz GIF File Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27768 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2008 12:00AM |
| Updated: | Feb 13 2008 09:16PM |
| Credit: | Tomas Hoger discovered this issue. |
| Vulnerable: |
Graphviz Graphviz 2.12 |
| Not Vulnerable: | |
Discussion
Graphviz GIF File Remote Buffer Overflow Vulnerability
Graphviz is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. The issue occurs when handling malformed GIF images.
Attackers can leverage this issue to execute arbitrary code in the context of an application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
This issue affects Graphviz 2.12; other versions may also be vulnerable.
NOTE: This issue may be related to the issues described in BID 19582.
Graphviz is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. The issue occurs when handling malformed GIF images.
Attackers can leverage this issue to execute arbitrary code in the context of an application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
This issue affects Graphviz 2.12; other versions may also be vulnerable.
NOTE: This issue may be related to the issues described in BID 19582.
Exploit / POC
Graphviz GIF File Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Graphviz GIF File Remote Buffer Overflow Vulnerability
Solution:
Updated Graphviz packages for Fedora 7 are available. Please see the references for more information.
Solution:
Updated Graphviz packages for Fedora 7 are available. Please see the references for more information.
References
Graphviz GIF File Remote Buffer Overflow Vulnerability
References:
References:
- Bugzilla Bug 431568: CVE-2006-4484 gd: GIF handling buffer overflow (Red Hat)
- Graphviz Homepage (Graphviz)