CVE-2008-0553
Title: Tcl Tk RCE
Memory Corruption
Proof Of Concept
No public PoC currently indexed for CVE-2008-0553.
CWE Category
CWE-119
Published Date
Feb 07, 2008
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
6.8
CVSS v2.0
Exploit Probability (EPSS)
4.25%
Vulnerability Summary
CVE-2008-0553: Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.
Impacted Vendors
Reference Links
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://secunia.com/advisories/28784
http://secunia.com/advisories/28807
http://secunia.com/advisories/28848
http://secunia.com/advisories/28857
http://secunia.com/advisories/28867
http://secunia.com/advisories/28954
http://secunia.com/advisories/29069
http://secunia.com/advisories/29070
http://secunia.com/advisories/29622
http://secunia.com/advisories/30129
http://secunia.com/advisories/30188
http://secunia.com/advisories/30535
http://secunia.com/advisories/30717
http://secunia.com/advisories/30783
http://secunia.com/advisories/32608
http://securitytracker.com/id?1019309
http://sourceforge.net/project/shownotes.php?release_id=573933&group_id=10894
http://sunsolve.sun.com/search/document.do?assetkey=1-26-237465-1
http://ubuntu.com/usn/usn-664-1
http://wiki.rpath.com/Advisories:rPSA-2008-0054
http://www.debian.org/security/2008/dsa-1490
http://www.debian.org/security/2008/dsa-1491
http://www.debian.org/security/2008/dsa-1598
http://www.mandriva.com/security/advisories?name=MDVSA-2008:041
http://www.novell.com/linux/security/advisories/2008_13_sr.html
http://www.redhat.com/support/errata/RHSA-2008-0134.html
http://www.redhat.com/support/errata/RHSA-2008-0135.html
http://www.redhat.com/support/errata/RHSA-2008-0136.html
http://www.securityfocus.com/archive/1/488069/100/0/threaded
http://www.securityfocus.com/archive/1/493080/100/0/threaded
http://www.securityfocus.com/bid/27655
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
http://www.vupen.com/english/advisories/2008/0430
http://www.vupen.com/english/advisories/2008/1456/references
http://www.vupen.com/english/advisories/2008/1744
https://bugzilla.redhat.com/show_bug.cgi?id=431518
https://issues.rpath.com/browse/RPL-2215
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10098
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00115.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00132.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00193.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00205.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00116.html
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://secunia.com/advisories/28784
http://secunia.com/advisories/28807
http://secunia.com/advisories/28848
http://secunia.com/advisories/28857
http://secunia.com/advisories/28867
http://secunia.com/advisories/28954
http://secunia.com/advisories/29069
http://secunia.com/advisories/29070
http://secunia.com/advisories/29622
http://secunia.com/advisories/30129
http://secunia.com/advisories/30188
http://secunia.com/advisories/30535
http://secunia.com/advisories/30717
http://secunia.com/advisories/30783
http://secunia.com/advisories/32608
http://securitytracker.com/id?1019309
http://sourceforge.net/project/shownotes.php?release_id=573933&group_id=10894
http://sunsolve.sun.com/search/document.do?assetkey=1-26-237465-1
http://ubuntu.com/usn/usn-664-1
http://wiki.rpath.com/Advisories:rPSA-2008-0054
http://www.debian.org/security/2008/dsa-1490
http://www.debian.org/security/2008/dsa-1491
http://www.debian.org/security/2008/dsa-1598
http://www.mandriva.com/security/advisories?name=MDVSA-2008:041
http://www.novell.com/linux/security/advisories/2008_13_sr.html
http://www.redhat.com/support/errata/RHSA-2008-0134.html
http://www.redhat.com/support/errata/RHSA-2008-0135.html
http://www.redhat.com/support/errata/RHSA-2008-0136.html
http://www.securityfocus.com/archive/1/488069/100/0/threaded
http://www.securityfocus.com/archive/1/493080/100/0/threaded
http://www.securityfocus.com/bid/27655
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
http://www.vupen.com/english/advisories/2008/0430
http://www.vupen.com/english/advisories/2008/1456/references
http://www.vupen.com/english/advisories/2008/1744
https://bugzilla.redhat.com/show_bug.cgi?id=431518
https://issues.rpath.com/browse/RPL-2215
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10098
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00115.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00132.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00193.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00205.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00116.html
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:P/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2008-0553 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Stack
No specific products linked.