Candidate: CVE-2010-0991 PublicDate: 2010-04-22 14:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0991 http://seclists.org/bugtraq/2010/Apr/196 Description: Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafted (1) ARGB, (2) XPM, or (3) BMP file, related to the IMAGE_DIMENSIONS_OK macro in lib/image.h. Ubuntu-Description: Notes: mdeslaur> only affects 1.4.3 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_imlib2: upstream_imlib2: needs-triage dapper_imlib2: ignored (reached end-of-life) hardy_imlib2: not-affected (1.4.0-1ubuntu1.2) intrepid_imlib2: not-affected (1.4.0-1.1ubuntu1.1) jaunty_imlib2: not-affected (1.4.2-4ubuntu1) karmic_imlib2: not-affected (1.4.2-5) devel_imlib2: not-affected (1.4.2-5build1)