CVE-2008-2426 describes multiple stack-based buffer overflows in Imlib 2 (imlib2) version 1.4.0. Specifically, it affects the handling of crafted PNM and XPM image files, leading to vulnerabilities in the load functions within src/modules/loaders/loader_pnm.c and src/modules/loader_xpm.c. This vulnerability carries a critical CVSS score of 9.3, indicating that a user-assisted remote attacker could exploit it with medium complexity to cause a denial of service (crash) or potentially execute arbitrary code, resulting in complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:carsten_haitzler:imlib2:1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.