An error when processing RLE compressed images can be exploited to cause a heap-based buffer overflow via a specially crafted BMP image containing many "End of Line" markers within a stream.
The Code
http://protekresearchlab.com/exploits/PRL-2012-32.rle
http://www.exploit-db.com/sploits/PRL-2012-32.rle.tar.gz
Disclosure Timeline:
2012-07-11 - Vulnerability reported to secunia
2012-11-12 - Coordinated public release of advisory