Twibright Labs Links Large PNG Image Buffer Overflow Vulnerability
BID:4921
Info
Twibright Labs Links Large PNG Image Buffer Overflow Vulnerability
| Bugtraq ID: | 4921 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jun 03 2002 12:00AM |
| Credit: | Vulnerability first detailed in the project changelog. |
| Vulnerable: |
Twibright Labs Links 2.0 pre4 |
| Not Vulnerable: |
Twibright Labs Links 2.0 pre6 Twibright Labs Links 2.0 pre5 |
Discussion
Twibright Labs Links Large PNG Image Buffer Overflow Vulnerability
Twibright Labs' Links is vulnerable to a buffer overflow condition when processing overly large 16-bit PNG images. This potentially exploitable issue may enable an attacker to execute arbitrary code as the user running the vulnerable client. At the very least, it is possible for a malicious webpage to cause the client to crash, resulting in a denial of service.
The browser must be in graphics mode for this to be an issue.
Twibright Labs' Links is vulnerable to a buffer overflow condition when processing overly large 16-bit PNG images. This potentially exploitable issue may enable an attacker to execute arbitrary code as the user running the vulnerable client. At the very least, it is possible for a malicious webpage to cause the client to crash, resulting in a denial of service.
The browser must be in graphics mode for this to be an issue.
Solution / Fix
Twibright Labs Links Large PNG Image Buffer Overflow Vulnerability
Solution:
The vendor has issued fixes to address this vulnerability.
Twibright Labs Links 2.0 pre4
Solution:
The vendor has issued fixes to address this vulnerability.
Twibright Labs Links 2.0 pre4
-
Twibright Labs links-2.0pre6.tar.gz
ftp://atrey.karlin.mff.cuni.cz/pub/local/clock/links/links-2.0pre6.tar .gz