VulnerabilityModified
CVE-2008-0553
Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
MEDIUM 6.8EPSS 4.25%
Does this matter?
Lower severity and a low EPSS score (4.25%). Track it; it rarely justifies an emergency change on its own.
Description
Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.25% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- tcl tk/tcl tk
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
- http://secunia.com/advisories/28784Patch, Vendor Advisory
- http://secunia.com/advisories/28807Vendor Advisory
- http://secunia.com/advisories/28848Vendor Advisory
- http://secunia.com/advisories/28857Vendor Advisory
- http://secunia.com/advisories/28867Vendor Advisory
- http://secunia.com/advisories/28954Vendor Advisory
- http://secunia.com/advisories/29069Vendor Advisory
- http://secunia.com/advisories/29070Vendor Advisory
- http://secunia.com/advisories/29622Vendor Advisory
- http://secunia.com/advisories/30129Vendor Advisory
- http://secunia.com/advisories/30188Vendor Advisory
- http://secunia.com/advisories/30535Vendor Advisory
- http://secunia.com/advisories/30717Vendor Advisory
- http://secunia.com/advisories/30783Vendor Advisory
- http://secunia.com/advisories/32608
- http://securitytracker.com/id?1019309
- http://sourceforge.net/project/shownotes.php?release_id=573933&group_id=10894
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-237465-1
- http://ubuntu.com/usn/usn-664-1
- http://wiki.rpath.com/Advisories:rPSA-2008-0054
- http://www.debian.org/security/2008/dsa-1490
- http://www.debian.org/security/2008/dsa-1491
- http://www.debian.org/security/2008/dsa-1598
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:041
- http://www.novell.com/linux/security/advisories/2008_13_sr.html
- http://www.redhat.com/support/errata/RHSA-2008-0134.html
- http://www.redhat.com/support/errata/RHSA-2008-0135.html
- http://www.redhat.com/support/errata/RHSA-2008-0136.html
- http://www.securityfocus.com/archive/1/488069/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.