An integer truncation error when processing Sun Raster images can be exploited to cause a heap-based buffer overflow via a specially crafted "Depth" value in a RAS file. Proof of concept included.
deec59b7511a6a5f9b798bbeb76b449e5acbef7e088fb4533468afed85672740