SDL_image 1.2.6 - Invalid '.GIF' File LWZ Minimum Code Size Remote Buffer Overflow
Author: Gynvael Coldwind
type: dos
platform: linux
port:
date_added: 2008-01-23
date_updated: 2014-01-23
verified: 1
codes: CVE-2007-6697;OSVDB-42374
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/27417/info
The SDL_image library is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. The issue occurs when handling malformed GIF images.
Attackers can leverage this issue to execute arbitrary code in the context of an application using the library. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Versions prior to SDL_image 1.2.7 are vulnerable.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31054.gif