10
CVSSv2

CVE-2004-0914

Published: 10/01/2005 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple vulnerabilities in libXpm for 6.8.1 and previous versions, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote malicious users to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

Vulnerable Product Search on Vulmon Subscribe to Product

lesstif lesstif 0.93.34

lesstif lesstif 0.93.36

x.org x11r6 6.8.1

xfree86 project x11r6 3.3

xfree86 project x11r6 4.0.2.11

xfree86 project x11r6 4.0.3

xfree86 project x11r6 4.3.0

lesstif lesstif 0.93.40

lesstif lesstif 0.93.91

xfree86 project x11r6 3.3.2

xfree86 project x11r6 3.3.3

xfree86 project x11r6 3.3.4

xfree86 project x11r6 4.1.0

xfree86 project x11r6 4.1.11

lesstif lesstif 0.93

lesstif lesstif 0.93.94

lesstif lesstif 0.93.96

xfree86 project x11r6 3.3.5

xfree86 project x11r6 3.3.6

xfree86 project x11r6 4.1.12

xfree86 project x11r6 4.2.0

lesstif lesstif 0.93.12

lesstif lesstif 0.93.18

x.org x11r6 6.7.0

x.org x11r6 6.8

xfree86 project x11r6 4.0

xfree86 project x11r6 4.0.1

xfree86 project x11r6 4.2.1

suse suse linux 8

suse suse linux 9.0

gentoo linux

redhat fedora core core_2.0

suse suse linux 9.1

suse suse linux 9.2

redhat fedora core core_3.0

suse suse linux 1.0

suse suse linux 8.1

suse suse linux 8.2

Vendor Advisories

Synopsis XFree86 security update Type/Severity Security Advisory: Moderate Topic Updated XFree86 packages that fix several security flaws in libXpm are nowavailable for Red Hat Enterprise Linux 3 Description XFree86 is an open source implementation of the X Window System Itprovides the ba ...
Synopsis openmotif security update Type/Severity Security Advisory: Important Topic Updated openmotif packages that fix flaws in the Xpm image library are nowavailable Description OpenMotif provides libraries which implement the Motif industry standardgraphical user interface During a so ...
Several vulnerabilities have been found in the XPM image decoding functions of the LessTif library If an attacker tricked a user into loading a malicious XPM image with an application that uses LessTif, he could exploit this to execute arbitrary code in the context of the user opening the image ...
USN-83-1 fixed some vulnerabilities in the “lesstif2” library The older “lesstif1” library was also affected, however, a fix was not yet available at that time This USN fixes the flaws for lesstif1 ...