Files
CVEs-PoC/2007/CVE-2007-1667.md
T
2025-09-29 21:09:30 +02:00

18 lines
877 B
Markdown

### [CVE-2007-1667](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.
### POC
#### Reference
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9776
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds