Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libtk-img | Jul 30, 2024 | Sep 28, 2007 |
| Freebsd | — | Upgrade tkUpgrade tk-threads | Dec 10, 2025 | Oct 5, 2007 |
| Oracle_linux | — | Upgrade tkUpgrade tk-devel | Oct 16, 2024 | Sep 28, 2007 |
| Suse | — | Upgrade tk-x86Upgrade tk-64bitUpgrade tk-32bitUpgrade suse-releaseUpgrade tk-develUpgrade tk | Dec 12, 2013 | Sep 28, 2007 |
| Ubuntu | — | Upgrade tk8.3Upgrade tk8.4 | Nov 8, 2024 | Sep 28, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub