pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read.
https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00069.html
https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00058.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/46054
http://www.securityfocus.com/bid/31871
http://www.openwall.com/lists/oss-security/2008/10/23/2
http://www.openwall.com/lists/oss-security/2008/10/22/7
http://netpbm.svn.sourceforge.net/viewvc/netpbm/stable/doc/HISTORY