Bugzilla – Bug 59305
VUL-0: CVE-2004-0802: bmp loader buffer overflow in imlib2
Last modified: 2021-10-04 10:01:27 UTC
there is a image loader buffer overflow in the BMP image loader in imlib2, very similar to the one in imlib and xv. Fixed by following patch. This is a 9.0 and 9.1 box only library fortunately..
<!-- SBZ_reproduce --> I dont know of an image viewer using imlib2 at the moment.
Created attachment 22958 [details] imlib2-1.1.0-fix.patch
this additionaly disables the /tmp loissage gzbz2 handler, which is fixed in 1.1.1.
CAN-2004-0802
submitted packages and patchinfo.
released
CVE-2004-0802: CVSS v2 Base Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)