|
Chris Evans reported several flaws (stack and integer overflows) in theXpm library code that parses image files (CAN-2004-0687, CAN-2004-0688).Some of these would be exploitable when parsing malicious image files inan application that handles XPM images, if they could escape ProPolice. |