|
A local overflow exists in xv. xv fails to check the integer length for user supplied input to xvpm.c functions resulting in heap overflow. With a specially crafted image file, an attacker can cause arbitrary code to be executed resulting in a loss of integrity.
|