|
A local overflow exists in xv. xv fails to check integer length for user supplied input to xvpcx.c functions resulting in a heap overflow. With a specially crafted image file, an attacker can cause arbitrary code to be executed resulting in a loss of integrity.
|