SDL_image 1.2.6 - Invalid '.GIF' File LWZ Minimum Code Size Remote Buffer Overflow

EDB-ID:

31054


Platform:

Linux

Published:

2008-01-23

source: http://www.securityfocus.com/bid/27417/info

The SDL_image library is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. The issue occurs when handling malformed GIF images.

Attackers can leverage this issue to execute arbitrary code in the context of an application using the library. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.

Versions prior to SDL_image 1.2.7 are vulnerable. 

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/31054.gif