Lucene search

K
ibmIBMCA4F5EF48225A9B77EA67A9DD5D8218BD9B8EED8CC32FA43BE980E940762EC8C
HistoryJun 16, 2018 - 7:52 p.m.

Security Bulletin: IBM Forms Viewer can crash on some embedded PNG images (CVE-2013-6954)

2018-06-1619:52:50
www.ibm.com
26

EPSS

0.133

Percentile

95.6%

Summary

A XFDL form with a PNG image that exposes this issue can crash the IBM Forms Viewer

Vulnerability Details

CVEID: CVE-2013-6954

DESCRIPTION:

A XFDL form can be created utilizing a specially created PNG image that could result in the IBM Forms Viewer to crash.

CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/89917&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

Affected Products and Versions

IBM Forms Viewer 4.0
IBM Forms Viewer 8.0
IBM Forms Viewer 8.0.1

Remediation/Fixes

Product

| VRMF|APAR|Remediation
—|—|—|—
IBM Forms Viewer| 4.0.0.| LO79835| Install IBM Forms Viewer 4.0.0.3 CF1 from Fix Central
IBM Forms Viewer| 8.0.0.
| LO79835| Install IBM Forms Viewer 8.0.1.1 CF1 from Fix Central
IBM Forms Viewer| 8.0.1.*| LO79835| Install IBM Forms Viewer 8.0.1.1 CF1 from Fix Central

Workarounds and Mitigations

To expose this issue, the user will have to be directed to open this specifically crafted form that uses a PNG image that exposes this issue.