[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0914Date: (C)2005-01-10   (M)2023-12-22


Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-11694
SECUNIA-13224
DSA-607
FEDORA-2004-433
FLSA-2006:152803
GLSA-200411-28
GLSA-200502-06
GLSA-200502-07
HPSBTU01228
MDKSA-2004:137
RHSA-2004:537
RHSA-2004:610
RHSA-2005:004
USN-83-1
USN-83-2
http://www.x.org/pub/X11R6.8.1/patches/README.xorg-681-CAN-2004-0914.patch
libxpm-command-execution(18145)
libxpm-directory-traversal(18146)
libxpm-dos(18147)
libxpm-image-bo(18142)
libxpm-improper-memory-access(18144)
oval:org.mitre.oval:def:9943

CPE    6
cpe:/o:suse:suse_linux:9.2
cpe:/o:suse:suse_linux:9.0
cpe:/o:suse:suse_linux:8.1
cpe:/o:suse:suse_linux:9.1
...

© SecPod Technologies