Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5378

Опубликовано: 12 окт. 2007
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tcl_tk:tk_toolkit:*:*:*:*:*:*:*:*
Версия до 8.3.5 (включая)
cpe:2.3:a:tcl_tk:tk_toolkit:*:*:*:*:*:*:*:*
Версия до 8.4.12 (включая)

EPSS

Процентиль: 79%
0.01359
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 18 лет назад

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

redhat
больше 19 лет назад

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

debian
почти 18 лет назад

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolk ...

github
больше 3 лет назад

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 79%
0.01359
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-119