Tielei Wang has discovered a vulnerability in wxWidgets, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an integer overflow error within the "wxImage::Create()" function in src/common/image.cpp. This can be exploited to cause a heap-based buffer overflow by tricking a user into opening e.g. a specially crafted JPEG file. Successful exploitation may allow execution of arbitrary code. The vulnerability is confirmed in version 2.8.10. Other versions may also be affected.
> wxGTK-2.8.9-alt2.src.rpm *** This bug has been marked as a duplicate of bug 20328 ***