CVE-2007-5137
libtk-img - arbitrary code execution
EPSS 4.9%
Description
Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378.
How to fix CVE-2007-5137
To remediate CVE-2007-5137, upgrade the affected package to a fixed version below.
- Debian/libtk-img—upgrade to 1.3-release-8 or later
- Debian/libtk-img—upgrade to 1:1.3-15etch3 or later
Is CVE-2007-5137 being exploited?
Low — EPSS is 4.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.3-release-8
- from 0, < 1:1.3-15etch3