Title : Gentoo Security Update Fixes Kdegraphics Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-0556 CVE ID : CVE-2006-0301
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-02-13
Technical Description
Gentoo has released updated packages to address a vulnerability identified in Kdegraphics. This flaw is due to a heap overflow error when processing malformed splash images that produce certain values that exceed the "width" or "height" of the associated bitmap, which could be exploited by attackers to execute arbitrary code. For additional information, see : VUPEN/ADV-2006-0389