FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

tcl/tk -- buffer overflow in ReadImage function

Affected packages
8.2.* < tk < 8.2.3_11
8.3.* < tk < 8.3.5_10
8.4.*,2 < tk < 8.4.16,2
8.2.* < tk-threads < 8.2.3_11
8.3.* < tk-threads < 8.3.5_10
8.4.*,2 < tk-threads < 8.4.16,2

Details

VuXML ID a058d6fa-7325-11dc-ae10-0016179b2dd5
Discovery 2007-09-27
Entry 2007-10-05
Modified 2011-09-04

A Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl/Tk, allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first.

References

CVE Name CVE-2007-5137
URL http://secunia.com/advisories/26942
URL http://sourceforge.net/project/shownotes.php?release_id=541207