CVE-2008-5262
devil - arbitrary code execution
EPSS 3.2%
Description
Multiple stack-based buffer overflows in the iGetHdrHeader function in src-IL/src/il_hdr.c in DevIL 1.7.4 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE file.
How to fix CVE-2008-5262
To remediate CVE-2008-5262, upgrade the affected package to a fixed version below.
- Debian/devil—upgrade to 1.7.5-4 or later
- Debian/devil—upgrade to 1.6.7-5+etch1 or later
- Debian/devil—upgrade to 1.6.8-rc2-3+lenny1 or later
Is CVE-2008-5262 being exploited?
Low — EPSS is 3.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.7.5-4
- from 0, < 1.6.7-5+etch1
- from 0, < 1.6.8-rc2-3+lenny1