Description
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1037-1 | New zgv packages fix arbitrary code execution |
Debian DSA |
DSA-1038-1 | New xzgv packages fix arbitrary code execution |
EUVD |
EUVD-2006-1064 | Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T16:56:15.524Z
Reserved: 2006-03-07T00:00:00.000Z
Link: CVE-2006-1060
No data.
Status : Modified
Published: 2006-04-11T10:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-1060
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD