Candidate: CVE-2010-1513 PublicDate: 2010-05-26 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1513 Description: Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ziproxy: upstream_ziproxy: released (3.0.1) dapper_ziproxy: DNE hardy_ziproxy: DNE jaunty_ziproxy: ignored (reached end-of-life) karmic_ziproxy: ignored (reached end-of-life) lucid_ziproxy: ignored (reached end-of-life) maverick_ziproxy: ignored (reached end-of-life) natty_ziproxy: not-affected (3.1.3-1) oneiric_ziproxy: not-affected (3.1.3-1) precise_ziproxy: not-affected (3.1.3-1) quantal_ziproxy: not-affected (3.1.3-1) raring_ziproxy: not-affected (3.1.3-1) saucy_ziproxy: not-affected (3.1.3-1) devel_ziproxy: not-affected (3.1.3-1)