CVE-2009-4274 - CVE House
Back to Database
Status published High CVE-2009-4274

Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows...

Vulnerability Description

Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4274

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

netpbm
Vulnerable Versions:
10.0, 10.1, 10.2, 10.3, 10.4, 10.5, 10.6, 10.7, 10.8, 10.9, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23, 10.24, 10.25, 10.26, 10.27, 10.28, 10.29, 10.30, 10.31, 10.32, 10.33, 10.34, 10.35.00, 10.35.01, 10.35.02, 10.35.03, 10.35.04, 10.35.05, 10.35.06, 10.35.07, 10.35.08, 10.35.09, 10.35.10, 10.35.11, 10.35.12, 10.35.13, 10.35.14, 10.35.15, 10.35.16, 10.35.17, 10.35.18, 10.35.19, 10.35.20, 10.35.21, 10.35.22, 10.35.23, 10.35.24, 10.35.25, 10.35.26, 10.35.27, 10.35.28, 10.35.29, 10.35.30, 10.35.31, 10.35.32, 10.35.33, 10.35.34, 10.35.35, 10.35.36, 10.35.37, 10.35.38, 10.35.39, 10.35.40, 10.35.41, 10.35.42, 10.35.43, 10.35.44, 10.35.45, 10.35.46, 10.35.47, 10.36.00, 10.37.00, 10.38.00, 10.39.00, 10.40.00, 10.41.00, 10.42.00, 10.43.00, 10.44.00, 10.45.00, 10.46.00, 10.47.00, 10.47.01, 10.47.02, 10.47.03, 10.47.04, 10.47.05, 10.47.06

Timeline

Official Publish: February 12th, 2010
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.