CVE-2009-2294
Priority
Low
Description
Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and
earlier allows remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a PNG image with crafted (1) width or
(2) height values.
References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2294
Package
Source:
dillo
(
LP
Ubuntu
Debian
)
Upstream:
needs-triage
Ubuntu 8.04 LTS (Hardy Heron)
:
ignored
(reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):
DNE
Ubuntu 11.04 (Natty Narwhal):
DNE
Ubuntu 11.10 (Oneiric Ocelot):
DNE
Ubuntu 12.04 LTS (Precise Pangolin):
DNE
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2012-06-01 15:19:56 UTC (commit
5347
)