Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111358557823673&w=2 | mailing list |
http://www.overflow.pl/adv/gocr.txt | exploit vendor advisory |