CVE-2008-0544

NameCVE-2008-0544
DescriptionHeap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file. NOTE: some of these details are obtained from third party information.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1493-1, DSA-1493-2
NVD severityhigh (attack range: remote)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sdl-image1.2 (PTS)squeeze1.2.10-2fixed
wheezy1.2.12-2fixed
stretch, jessie, sid1.2.12-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sdl-image1.2source(unstable)1.2.6-3medium
sdl-image1.2sourceetch1.2.5-2+etch1highDSA-1493-2
sdl-image1.2sourcesarge1.2.4-1etch1highDSA-1493-2

Search for package or bug name: Reporting problems