econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://anonscm.debian.org/gitweb/?p=collab-maint/exactimage.git%3Ba=commitdiff%3Bh=1dff2eb586a3d10d8528a984bc471292e3789f5c%3Bhp=acfe54193b18b46e880f4b474d2e40b4fdb44a8d - | |
References | () http://www.debian.org/security/2013/dsa-2754 - | |
References | () http://www.openwall.com/lists/oss-security/2013/09/05/8 - Patch |
Information
Published : 2013-09-16 19:14
Updated : 2025-04-11 00:51
NVD link : CVE-2013-1441
Mitre link : CVE-2013-1441
CVE.ORG link : CVE-2013-1441
JSON object : View
Products Affected
exactcode
- exactimage
CWE
CWE-20
Improper Input Validation