CVE-2007-1667
HIGH severity · CVSS 9.3 · CWE-189
9.3CVSS HIGH
Summary
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)5%
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414045Advisory
- http://issues.foresightlinux.org/browse/FL-223
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlAdvisory
- http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2007-0125.htmlAdvisory
- http://secunia.com/advisories/24739
- http://secunia.com/advisories/24741
- http://secunia.com/advisories/24745