CVE-2009-2286

Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:james_ashton:compface:*:*:*:*:*:*:*:*
cpe:2.3:a:james_ashton:compface:1.4:*:*:*:*:*:*:*
cpe:2.3:a:james_ashton:compface:1.5:*:*:*:*:*:*:*
cpe:2.3:a:james_ashton:compface:1.5.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534973 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534973 -
References () http://www.openwall.com/lists/oss-security/2009/06/29/2 - () http://www.openwall.com/lists/oss-security/2009/06/29/2 -
References () http://www.openwall.com/lists/oss-security/2009/06/29/4 - () http://www.openwall.com/lists/oss-security/2009/06/29/4 -
References () http://www.openwall.com/lists/oss-security/2009/07/03/1 - () http://www.openwall.com/lists/oss-security/2009/07/03/1 -
References () http://www.securityfocus.com/bid/35863 - () http://www.securityfocus.com/bid/35863 -

Information

Published : 2009-07-01 13:00

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2286

Mitre link : CVE-2009-2286

CVE.ORG link : CVE-2009-2286


JSON object : View

Products Affected

james_ashton

  • compface
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer