Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xemacs21 | Jul 30, 2024 | Aug 5, 2009 |
| Gentoo Linux | — | Upgrade app-editors/xemacs. | Oct 30, 2017 | Aug 5, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 25, 2009 |
| Suse | — | Upgrade xemacs-infoUpgrade xemacs-elUpgrade xemacs | Feb 17, 2015 | Aug 5, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub