HIGH
xemacs: multiple integer overflow flaws
Published Aug 5, 2009
10.0
HIGHCVSS 2.0
EPSS 8.64%
Description
Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://osvdb.org/55298 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/35348 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://tracker.xemacs.org/XEmacs/its/issue534 x_refsource_MISC
- http://www.securityfocus.com/bid/35473 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/1666 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-2688 Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=275397 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=511994 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51332 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51333 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51334 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-2688
- https://www.cve.org/CVERecord?id=CVE-2009-2688
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/55298 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/35348 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://tracker.xemacs.org/XEmacs/its/issue534 | x_refsource_MISC | |
| http://www.securityfocus.com/bid/35473 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2009/1666 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2009-2688 | Vendor Advisory | |
| https://bugs.gentoo.org/show_bug.cgi?id=275397 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=511994 | x_refsource_CONFIRMIssue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51332 | vdb-entryx_refsource_XF | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51333 | vdb-entryx_refsource_XF | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51334 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2688 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-2688 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 5, 2009
Updated Aug 7, 2024
Reserved Aug 5, 2009
Link CVE-2009-2688
CISA Vulnrichment
Updated n/a