CVE-2008-0553

Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
tcl_tktcl_tk
𝑥
≤ 8.4.17
tcl_tktcl_tk
2.1
tcl_tktcl_tk
3.3
tcl_tktcl_tk
4.0p1:p1
tcl_tktcl_tk
6.1
tcl_tktcl_tk
6.1p1:p1
tcl_tktcl_tk
6.2
tcl_tktcl_tk
6.4
tcl_tktcl_tk
6.5
tcl_tktcl_tk
6.6
tcl_tktcl_tk
6.7
tcl_tktcl_tk
7.0
tcl_tktcl_tk
7.1
tcl_tktcl_tk
7.3
tcl_tktcl_tk
7.4
tcl_tktcl_tk
7.5
tcl_tktcl_tk
7.5p1:p1
tcl_tktcl_tk
7.6
tcl_tktcl_tk
7.6p2:p2
tcl_tktcl_tk
8.0
tcl_tktcl_tk
8.0.3
tcl_tktcl_tk
8.0.4
tcl_tktcl_tk
8.0.5
tcl_tktcl_tk
8.0p2:p2
tcl_tktcl_tk
8.1
tcl_tktcl_tk
8.1.1
tcl_tktcl_tk
8.2.0
tcl_tktcl_tk
8.2.1
tcl_tktcl_tk
8.2.2
tcl_tktcl_tk
8.2.3
tcl_tktcl_tk
8.3.0
tcl_tktcl_tk
8.3.1
tcl_tktcl_tk
8.3.2
tcl_tktcl_tk
8.3.3
tcl_tktcl_tk
8.3.4
tcl_tktcl_tk
8.3.5
tcl_tktcl_tk
8.4.0
tcl_tktcl_tk
8.4.1
tcl_tktcl_tk
8.4.2
tcl_tktcl_tk
8.4.3
tcl_tktcl_tk
8.4.4
tcl_tktcl_tk
8.4.5
tcl_tktcl_tk
8.4.6
tcl_tktcl_tk
8.4.7
tcl_tktcl_tk
8.4.8
tcl_tktcl_tk
8.4.9
tcl_tktcl_tk
8.4.10
tcl_tktcl_tk
8.4.11
tcl_tktcl_tk
8.4.12
tcl_tktcl_tk
8.4.13
tcl_tktcl_tk
8.4.14
tcl_tktcl_tk
8.4.15
tcl_tktcl_tk
8.4.16
tcl_tktcl_tk
8.4a2:a2
tcl_tktcl_tk
8.4a3:a3
tcl_tktcl_tk
8.4a4:a4
tcl_tktcl_tk
8.4b1:b1
tcl_tktcl_tk
8.4b2:b2
tcl_tktcl_tk
8.5.0
tcl_tktcl_tk
8.5_a3:_a3
tcl_tktcl_tk
8.5a1:a1
tcl_tktcl_tk
8.5a2:a2
tcl_tktcl_tk
8.5a3:a3
tcl_tktcl_tk
8.5a4:a4
tcl_tktcl_tk
8.5a5:a5
tcl_tktcl_tk
8.5a6:a6
tcl_tktcl_tk
8.5b1:b1
tcl_tktcl_tk
8.5b2:b2
tcl_tktcl_tk
8.5b3:b3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libtk-img
bullseye
1:1.4.13+dfsg-1
fixed
bookworm
1:1.4.14+dfsg-2
fixed
sid
1:2.0.0+dfsg1-1
fixed
trixie
1:2.0.0+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tk8.0
intrepid
dne
hardy
dne
gutsy
dne
feisty
dne
edgy
dne
dapper
Fixed 8.0.5-11ubuntu0.1
released
tk8.3
intrepid
Fixed 8.3.5-12
released
hardy
Fixed 8.3.5-12
released
gutsy
Fixed 8.3.5-6ubuntu3.1
released
feisty
ignored
edgy
ignored
dapper
Fixed 8.3.5-4ubuntu1.2
released
tk8.4
intrepid
not-affected
hardy
Fixed 8.4.16-2ubuntu1.1
released
gutsy
Fixed 8.4.15-1ubuntu1.1
released
feisty
ignored
edgy
ignored
dapper
Fixed 8.4.12-0ubuntu1.2
released
tk8.5
intrepid
Fixed 8.5.0-3
released
hardy
Fixed 8.5.0-3
released
gutsy
dne
feisty
dne
edgy
dne
dapper
dne
References