9.3
CVSSv2

CVE-2007-0654

Published: 21/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote malicious users to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

x multimedia system x multimedia system 1.2.10

Vendor Advisories

Sven Krewitt of Secunia Research discovered that XMMS did not correctly handle BMP images when loading GUI skins If a user were tricked into loading a specially crafted skin, a remote attacker could execute arbitrary code with user privileges ...
Multiple errors have been found in the skin handling routines in xmms, the X Multimedia System These vulnerabilities could allow an attacker to run arbitrary code as the user running xmms by inducing the victim to load specially crafted interface skin files For the stable distribution (sarge), these problems have been fixed in version 1210+cvs2 ...