----------------------------------------------------------------------


  Secunia CSI
+ Microsoft SCCM
-----------------------
= Extensive Patch Management

http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/


----------------------------------------------------------------------

TITLE:
imlib2 "IMAGE_DIMENSIONS_OK()" Logic Error

SECUNIA ADVISORY ID:
SA39354

VERIFY ADVISORY:
http://secunia.com/advisories/39354/

DESCRIPTION:
Secunia Research has discovered a vulnerability in imlib2, which can
be exploited by malicious people to compromise an application using
the library.

The vulnerability is caused due to a logic error within the
"IMAGE_DIMENSIONS_OK()" macro in src/lib/image.h. This can be
exploited to cause heap-based buffer overflows via e.g. specially
crafted ARGB, XPM, and BMP image files.

The vulnerability is confirmed in version 1.4.3. Previous versions
are not affected.

SOLUTION:
Fixed in the SVN repository.

PROVIDED AND/OR DISCOVERED BY:
Stefan Cornelius, Secunia Research

ORIGINAL ADVISORY:
http://secunia.com/secunia_research/2010-54/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

----------------------------------------------------------------------