|
A local overflow exists in xv. xv fails to check the integer length for user supplied input to xviris.c functions resulting in multiple heap overflows. With a specially crafted image file, an attacker can cause arbitrary code to be executed resulting in a loss of integrity.
|