Giuseppe Iuculano
2009-Jul-15 18:44 UTC
[Secure-testing-team] Bug#537174: CVE-2009-2369: Integer overflow in the wxImage::Create function
Package: wxwidgets2.8 Severity: grave Tags: security patch -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for wxwidgets2.8. CVE-2009-2369[0]: | Integer overflow in the wxImage::Create function in | src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a | denial of service (crash) and possibly execute arbitrary code via a | crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: | the provenance of this information is unknown; the details are | obtained solely from third party information. If you fix the vulnerability please also make sure to include the CVE id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2369 http://security-tracker.debian.net/tracker/CVE-2009-2369 Patch: http://trac.wxwidgets.org/changeset/60875 http://trac.wxwidgets.org/changeset/60876 http://trac.wxwidgets.org/changeset/60897 Cheers, Giuseppe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkpeI6IACgkQNxpp46476ao5awCgjQl+5bM8qo94jOMVtWpZyGAK 5toAnjAKmNUXAkPypElmQY1l0q30hFZ3 =Comj -----END PGP SIGNATURE-----