CVE-2013-1953

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-1953 at MITRE

Description

Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow.

NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

SUSE information

SUSE Bugzilla entry: 815382

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 12.3
  • autotrace >= 0.31.1-637.4.1
  • autotrace-debuginfo >= 0.31.1-637.4.1
  • autotrace-debugsource >= 0.31.1-637.4.1
  • autotrace-devel >= 0.31.1-637.4.1
  • libautotrace3 >= 0.31.1-637.4.1
  • libautotrace3-debuginfo >= 0.31.1-637.4.1
Patchnames:
openSUSE-2013-515
openSUSE Evergreen 11.4
  • autotrace >= 0.31.1-629.1
  • autotrace-debuginfo >= 0.31.1-629.1
  • autotrace-debugsource >= 0.31.1-629.1
  • autotrace-devel >= 0.31.1-629.1
Patchnames:
2013-96