V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2007-1667
DEB
Critical

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for…

CVSS
9.3
Critical
EPSS
0.05
p90
Published
2007-01-01
Updated
2007-01-01
Description

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.

Tags · CWE
CWE-189
Affected products
Debian_linux
CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.046 · p90
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
XFree86Tracked
XFree86Tracked
graphicsmagickTracked
graphicsmagickTracked
imagemagickTracked
imagemagickTracked
libX11Tracked
libx11Tracked
libx11Tracked
xfree86Tracked
xorg-x11Tracked
xorg-x11-appsTracked
debian_linux*Tracked
libx11*Tracked
ubuntu_linux*Tracked