Integer overflow in image processing leads to buffer overflow.
vulners.com/securityvulns/securityvulns:doc:3767