CVE-2007-5137
Publication date 28 September 2007
Last updated 24 July 2024
Ubuntu priority
Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378.
Status
Package | Ubuntu Release | Status |
---|---|---|
libtk-img | ||
tk8.3 | ||
tk8.4 | ||
Notes
jdstrand
CVE only affects feisty and gutsy tk8.4. These releases have a fix for tcl/tk bug #1458234, which either introduced or unmasked the issue in this CVE (investigate). Bug #1458234 is a memory corruption crasher as well, and though it doesn't have a CVE, it should be fixed. tk8.3 is affected by #1458234 in all releases, so when fixing it, be sure to fix the CVE as well. tk8.4 in dapper and edgy need both fixes too.